Supply chain
β Supply Chain
Multiple US healthcare organizations and hospitals Third-Party Breach (March 2025)
Primary Source βIncident Details
Oracle Health breach compromises patient data at US hospitals. A breach at Oracle Health impacts multiple US healthcare organizations and hospitals after a threat actor stole patient data from legacy servers. Oracle Health has not yet publicly disclosed the incident, but in private communications sent to impacted customers and from conversations with those involved, BleepingComputer confirmed that patient data was stolen in the attack. Oracle Health, formerly known as Cerner, is a healthcare software-as-a-service (SaaS) company offering Electronic Health Records (EHR) and business operations systems to hospitals and healthcare organizations. After being acquired by Oracle in 2022, Cerner was merged into Oracle Health, with its systems migrated to Oracle Cloud. Third-party company: Oracle Health (formerly Cerner).
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Oracle Health (formerly Cerner)
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-03-01 Breach occurred
- 2025-03-28 Publicly disclosed