If a letter about the Oracle Health incident has arrived in your mail, or you were treated at a Texas hospital whose laboratory records ran through Cerner systems, the practical starting point is that a lawyer can read the notice you actually received. A filing reported to the Texas Attorney General puts the 2025 breach of legacy Cerner servers at nearly 20 million people, with as many as 2,992,244 Texas residents among them. This page sets out what the notices say, who in Texas they reach, and what kind of attorney reads a letter like this against one person’s records.
Status as of October 7, 2026. Breach reporting in this matter has arrived in stages over more than a year; the linked official notices are the current word.
Get a Texas Consumer Protection Lawyer — Now
A breach notice is a document with dates, data categories and an engagement number on it, and those details are what decide whether anything can be done. An experienced Texas attorney can read the letter you received against where the litigation already stands and explain what options may exist. Call or text 24/7. Get connected with an experienced consumer protection lawyer near you. Our referral service is free for the people we serve.
What Happened?
Oracle Health is the health-records business formerly known as Cerner Corporation. The systems involved were legacy Cerner data-migration servers that had not yet been moved to Oracle’s cloud — older infrastructure that still held historical patient records for hospitals and health systems around the country, including in Texas.
According to the account carried in the breach reporting, an unauthorized party used compromised customer credentials to reach those legacy servers beginning on or about January 22, 2025, and copied data to a remote server. Oracle Health identified the incident on or about February 20, 2025.
What was in the copied data varies by person. The notice published by CHRISTUS Health, a health system headquartered in Irving, Texas and one of the affected providers, describes the categories as names, Social Security numbers, and laboratory record information — which it lists as laboratory orders, blood bank records, medical record numbers, treating doctors, diagnoses, medications and test results. The same notice states that the affected data predates February 2025 and that present-day laboratory records are not involved.
Notification did not follow quickly, and the notices themselves explain why: federal investigators asked affected organizations to delay notifying individuals while the investigation proceeded. CHRISTUS says Oracle Health notified it in October 2025 and supplied its list of potentially affected patients on December 9, 2025, after which letters began going out. Other providers have been reaching patients later still.
How the Texas Number Surfaced
For most of the time this incident has been public, there was no total. Oracle Health did not initially state how many individuals were affected, and the count assembled slowly out of individual provider filings — at least 29 hospitals and health systems have been reported as affected, with figures such as 100,181 patients at Munson Healthcare and roughly 30,000 at ChristianaCare reported separately.
The statewide figure came from a Texas record. In the first week of October 2026, an update to the Texas Attorney General data breach reporting system was reported to show the incident at nearly 20 million individuals overall and as many as 2,992,244 Texas residents. That reporting is what put a number on the Texas share, and it is the largest Texas resident count attached to this incident so far.
Texas is the reason the figure exists at all. Under the Texas Identity Theft Enforcement and Protection Act, Texas Business and Commerce Code chapter 521, an organization that owns or licenses data covered by the statute must notify the Attorney General of a breach affecting at least 250 Texas residents no later than the 30th day after the breach is determined to have occurred, and must file that notice electronically. The reporting duty is what makes a count like this a public record rather than a private one.
Who Can Be Affected?
The people reached by this are not Oracle customers. They are patients — Texans who were treated at a hospital or health system whose laboratory or records systems ran on Cerner software before February 2025, often years before, and in many cases at a facility they no longer use.
Three groups are worth separating:
- Texans who have received a letter. The letter identifies the provider, the data categories involved for that person, an engagement number, and the services being offered. It is the single most useful document a lawyer can look at.
- Texans who believe they are affected but have had no letter. Notification in this matter has arrived in waves over more than a year, and some providers reached patients only in 2026. The absence of a letter is not by itself an answer either way.
- Texans whose Social Security number was involved. Provider notices describe Social Security numbers among the categories, and that is a different exposure from a medical record alone, because it reaches credit and identity rather than only health history.
CHRISTUS states in its notice that it is offering eligible patients a two-year membership in credit-monitoring and identity-protection services, and lists a dedicated telephone line and hours on its Oracle Health data incident page, where the engagement number from a letter is used to enroll. Other affected providers have published their own notices with their own terms.
What Kind of Claim Might Apply?
Litigation over this incident is not hypothetical and it is not new. Class-action complaints were filed in Missouri in April 2025, in Texas in November 2025 — later consolidated into broader proceedings — and in Georgia in November 2025. Whether a particular Texan falls inside or outside any of those proceedings is a question about that person’s provider, records and dates, not something a news page can answer.
Attorneys who handle data-breach matters in Texas generally describe several separate questions, and they are separate:
- Whether a person is within an existing class, or whether their situation sits outside it. Consolidation changes what joining looks like.
- Which entity the duty ran through — the vendor that held the legacy servers, or the provider that sent the records to it, or both. The notices name both kinds of organization.
- What the notice itself shows. The data categories listed for one person, and the gap between the date of the intrusion and the date of the letter, are facts on the page.
- Whether Texas health-records law is in play. The Texas Medical Records Privacy Act, Health and Safety Code chapter 181, reaches entities that handle protected health information in Texas and is broader in its definition of a covered entity than the federal rule.
- What enforcement, as opposed to a private claim, is available. Chapter 521 is enforced by the Attorney General, who may seek civil penalties; that is an enforcement route rather than a personal recovery.
None of that tells any individual what their own position is. It is the list of things a lawyer works through with the letter in hand.
Why Acting Quickly Can Matter
Two clocks are worth knowing about as facts.
The first is the limitations period. Texas Civil Practice and Remedies Code section 16.003 sets a two-year limitations period for negligence actions generally. How any limitations period applies to a specific person, a specific defendant and a specific date is one of the first things a lawyer examines, and in a matter where the intrusion happened in January 2025 and some letters did not arrive until 2026, those dates are not interchangeable.
The second is practical rather than legal: the credit-monitoring and identity-protection memberships described in the provider notices run for a stated term and are enrolled using the engagement number printed on an individual letter. Keeping the letter matters for that reason alone, and because it is the document that establishes which categories of data were involved for that person.
A breach that is already in consolidated litigation also moves on a schedule set by the courts rather than by the people affected, which is a reason many people ask a lawyer to look at the paperwork sooner rather than later.
Get a Texas Consumer Protection Lawyer — Now
Whether the question is a letter that just arrived, a Social Security number among the listed categories, a provider you have not used in years, or litigation you have read about and cannot place yourself in, an experienced Texas attorney can read the actual notice and explain what options may exist. Call or text 24/7. Get connected with an experienced consumer protection lawyer near you. If a lawyer in our network offers an initial consultation, it is free. Our referral service is free for the people we serve.
Sources
- CHRISTUS Health, Oracle Health Data Incident notice — the data categories, the January 22, 2025 start of unauthorized access, the law-enforcement request to delay notification, the October 2025 notification to CHRISTUS and the December 9, 2025 patient list, and the credit-monitoring and identity-protection offer (primary source).
- Texas Legislature, Texas Business and Commerce Code chapter 521, Identity Theft Enforcement and Protection Act — the breach-notification duty, the Attorney General reporting requirement and the enforcement provisions (primary source).
- Texas Legislature, Texas Health and Safety Code chapter 181, Medical Records Privacy — the Texas definition of a covered entity handling protected health information (primary source).
- Texas Legislature, Texas Civil Practice and Remedies Code section 16.003 — the two-year limitations period for negligence actions (primary source).
- “Texas AG Says Oracle Health 2025 Breach Affected 20M Individuals”, eSecurity Planet, October 7, 2026 — independent account of the Texas filing, the credential compromise, the February 20, 2025 discovery and the delayed notification.
- “Oracle Health breach impacts more than 20 million people, 3 million in Texas”, teiss, October 6, 2026 — second independent account, including the 2,992,244 Texas resident figure reported from the Attorney General data breach portal, the 29 affected health systems, and the Missouri, Texas and Georgia class actions.
- “Oracle 2025 Health Breach Compromised Data of 20 Million People”, Bloomberg, October 5, 2026 — the first report of the nearly 20 million figure drawn from the Texas filing.
- HIPAA Journal reporting on provider-level filings in the Oracle Health and Cerner incident — the pattern of individual health-system breach reports arriving in stages.
Find the right Texas lawyer for this: Texas Consumer Protection Attorneys · Texas Health Care Attorneys