Supply chain β›“ Supply Chain

Multiple US healthcare organizations and hospitals Third-Party Breach (March 2025)

πŸ“… 2025-03-01 🏒 Oracle Health (formerly Cerner)
Primary Source β†—

Incident Details

Oracle Health breach compromises patient data at US hospitals. A breach at Oracle Health impacts multiple US healthcare organizations and hospitals after a threat actor stole patient data from legacy servers. Oracle Health has not yet publicly disclosed the incident, but in private communications sent to impacted customers and from conversations with those involved, BleepingComputer confirmed that patient data was stolen in the attack. Oracle Health, formerly known as Cerner, is a healthcare software-as-a-service (SaaS) company offering Electronic Health Records (EHR) and business operations systems to hospitals and healthcare organizations. After being acquired by Oracle in 2022, Cerner was merged into Oracle Health, with its systems migrated to Oracle Cloud. Third-party company: Oracle Health (formerly Cerner).

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Oracle Health (formerly Cerner)
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-03-01 Breach occurred
  2. 2025-03-28 Publicly disclosed