Oracle Health Breach: Nearly 3 Million Texans Listed on the Attorney General's Portal. A Technician's Credit Freeze and Scam-Call Checklist for Austin Patients

Ready to get started?
Book a session or call us - we'll handle the rest.

Book a session or call us - we'll handle the rest.
The Texas Attorney General's data breach portal published a new entry from Cerner Corporation, now Oracle Health, on October 2, 2026, listing 2,992,244 affected people, and Bloomberg's reporting this week puts the national total near 20 million patients whose names, Social Security numbers, addresses and medical records were copied off old hospital servers. If you have been a patient at a Texas hospital or clinic in the last several years, this one is worth twenty minutes of your attention today, before the letter arrives and before the scam calls that follow every breach like this start.
We fix computers and networks in Austin homes all week, and the question we are already hearing is some version of "was that my hospital?" Here is what is actually known, what is not, and the steps that protect you whether or not your name is on the list.
Cerner is the electronic health record system behind a large share of American hospitals. Oracle bought it in 2022 and renamed it Oracle Health. According to Oracle's own notices to its hospital customers, an attacker used stolen customer credentials to get into legacy Cerner servers sometime after January 22, 2025, and copied patient data out. The servers were older systems that had not yet been moved to Oracle's cloud. Oracle told its hospital customers in March 2025 and left it to each hospital to decide who to notify.
For a year and a half the public numbers stayed small. Then on October 2 the Texas Attorney General's portal listed the Cerner entry at nearly 3 million people, and Bloomberg, reading that filing, reported the full breach touched nearly 20 million. The data types named in the filing and in the hospital notices that have gone out so far: name, Social Security number, home address, treating physicians, diagnoses, medications and test results.
Two things are still not known, and they matter for how you should act:
So the honest answer to "was that my hospital?" is: maybe, and you may not find out for a while. The steps below cost nothing and work either way.
A Social Security number plus a home address is everything a fraudster needs to open a credit card, a phone line or a loan in your name. A credit freeze stops that cold: no lender can pull your file to open a new account until you lift it. It is free by federal law, it takes about five minutes per bureau, and it does not affect your existing cards or your credit score.
Do it at all three, because a lender can use any one of them:
Write down the PIN or the login each bureau gives you and put it with your important papers. When you do need credit, a car loan next spring, say, you lift the freeze for a few days online and put it back.
If you have children who were patients, freeze their credit too. A child's Social Security number is more valuable to a thief precisely because nobody checks it for a decade.
A leaked Social Security number also means someone can file a tax return in your name in January and collect your refund before you do. The IRS Identity Protection PIN is a six-digit number the IRS requires on any return filed under your Social Security number. Anyone can request one at irs.gov/ippin with an ID.me account. It renews every year and it closes that door completely.
This breach is different from a retailer losing card numbers. Diagnoses, medications and physician names let someone impersonate you to a pharmacy, a clinic or your insurer. Medical identity theft shows up as:
Read every Explanation of Benefits for the next year instead of filing it unopened. If something is wrong, call the insurer at the number on your card and ask for your records to be flagged. You also have the right under HIPAA to request a copy of your medical record and ask for corrections.
Every large breach gets a second wave: scammers buy the stolen data and use the real details to sound legitimate. The calls and texts you should expect in Austin over the next few months:
The rule that beats all of them: hang up, and call back on the number printed on your insurance card or your hospital's own website. A real breach letter comes by postal mail from the hospital, not from Oracle, and a real credit-monitoring offer comes with an enrollment code in that letter, not a phone call asking for your details. Nobody legitimate takes payment in gift cards or asks you to move money "to a safe account." The broader pattern, and what we do about it in a home, is on our scam protection page.
Breach data gets used to reset passwords. Spend ten minutes on the accounts that matter:
If any of that sounds like a project, it is exactly the kind of hour we spend with customers who want it done right once. Our tech tutoring visits are built for walking a parent or a spouse through freezes, portals and two-factor setup at their own pace, at their own kitchen table.
Keep it. Enroll in the monitoring it offers, using the code in the letter and the website printed on it, typed by hand, not a link from an email. The monitoring is useful but it only alerts you after something happens; the freeze above is what prevents it. Note the date and the hospital on it; the letter is your proof if you ever need one.
None of it needs a technician. But if you would rather have someone sit beside you and do it with you, or you have an older relative whose records went through a Texas hospital and who answers every call, book a visit or send us a note. This is a good week to make the calls stop working.
Sources: the Texas Attorney General's data breach report portal (Cerner Corporation entry, published October 2, 2026); Bloomberg's October 2026 reporting on the filing; Christus Health's "Oracle Health Data Incident" notice.