iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Provider notices confirm that unauthorized access reached legacy Oracle Health/Cerner systems as early as January 22, 2025, and that patients associated with multiple providers may have been affected. But the available notices do not establish a verified total number of patients or hospitals, so describing the breach as “huge” is not supported by a confirmed aggregate count.
What happened in the Oracle Health breach?
Healthcare providers say Oracle Health, formerly Cerner, told them that an unauthorized third party accessed legacy Oracle Health/Cerner systems beginning as early as January 22, 2025. MedStar St. Mary’s describes the affected environment as Oracle Health data-migration systems. The notices concern information held in the vendor’s systems; they do not establish that every Oracle Health customer or patient was affected.
Provider notifications came later and on different timelines. LifeBridge Health’s notice is dated October 16, 2025, and says Oracle Health provided its potentially affected patient list on September 19, 2025. ChristianaCare says it received a list on September 29, 2025. UMC says Cerner notified it on October 20, 2025, and that UMC completed its review of the list on January 26, 2026. LifeBridge Health, ChristianaCare, and UMC published organization-specific notices.
How many people were affected?
A verified portfolio-wide patient or hospital total is not established by the provider notices cited here. An April 23, 2025 letter from Democratic members of the U.S. House Committee on Veterans’ Affairs described the patient count for the reported data-migration incident as unknown. That letter said its account relied in part on private communications and press reports. It is evidence that lawmakers were seeking answers, not a final public investigation finding or a confirmed count. Read the House committee letter.
#1 Best Overall
- Hardware encrypted drive
- Simple to use pin access. RPM-5400
- Administrator password feature
- Bus powered
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
The same letter discusses a separate reported Oracle Cloud Classic incident involving claims about customer security keys, encrypted credentials, LDAP entries, and other data. It also attributes reporting about a ransom demand to private communications and press coverage. These allegations should not be merged with the patient data-migration incident or treated as adjudicated findings.
What information may have been exposed?
The possible information differs by person and provider. Across their notices, examples include names, Social Security numbers, medical record numbers, doctors, diagnoses, medications, test results, images, and other care or treatment information. MedStar St. Mary’s also lists driver’s-license numbers, dates of birth, dates of service, and insurance information. These are examples across notices, not a single confirmed data set for every person whose information may have been involved.
Rank #2
- Utilizes Military Grade FIPS PUB 197 Validated Encryption Algorithm
- Super fast USB 3.0 Connection - Data transfer speeds up to 10X faster than USB 2.0
- Software Free Design - With no admin rights needed
- Sealed from Physical Attacks by Tough Epoxy Coating
- Brute Force Self Destruct Feature
For details tied to a specific provider, consult its notice: Tri-City Medical Center/Sharp HealthCare, ChristianaCare, LifeBridge Health, MedStar St. Mary’s Hospital, and UMC Health System.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteWere hospital systems or patient care disrupted?
The cited provider notices say their organizations’ current systems were not compromised and care was not disrupted in the reported cases. ChristianaCare states that its IT systems were not impacted and its clinical operations continued without disruption. Tri-City Medical Center says the incident did not involve patient information maintained by the organization or its current IT systems and did not disrupt clinical operations. Those are statements by the named organizations; they should not be generalized to every Oracle Health customer.
Quick Recap
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Rank #3
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
How to check whether your information was involved
- Look for a notice from your healthcare provider. Eligibility depends on the provider-specific patient list and notification process. A patient of an Oracle Health customer is not automatically confirmed as affected.
- Use the instructions in your own notice. Some providers offer complimentary credit monitoring or identity-protection services to the people they identified. Enrollment deadlines, eligibility, and contact numbers vary by provider, so use the details in the letter rather than assuming a service is available to everyone.
- Review provider and insurer statements. Check bills, explanation-of-benefits statements, and other account records. Promptly contact the provider or insurer about inaccuracies or charges for services you did not receive, as the notices advise.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

