Features

The Oracle Hearing: When Washington Finally Asked Who Owns the Code

HasuTiger

Hook: The Subpoena That Felt Like Déjà Vu

The news hit my feed at 6:47 AM Prague time—a Tuesday, which meant the US House committee had just wrapped its first round of questioning. Larry Ellison, the swashbuckling billionaire behind Oracle, was being called before Congress to explain his company's role in the Veterans Health Records modernization project. Not Oracle the entity. Not Oracle Health the subsidiary. Larry himself.

I've been in this industry long enough to know when a summons carries weight. And this one? It carries the weight of 18 years of deferred accountability.

Here's the thing that stopped me mid-coffee: the committee isn't just asking about missed deadlines or budget overruns. They're asking about the relationship between Ellison and a project that was supposed to give America's veterans a state-of-the-art digital health record system by 2024. That deadline came and went. The system? Still limping along, with VA pausing new site rollouts back in 2023.

We didn't dodge the chaos in Web3 when our projects failed. We danced through it—post-mortems, community calls, raw transparency. Now Washington is demanding the same from one of the most powerful tech executives on the planet.

The network breathes in Prague, pulses in Ethereum—but tonight, it holds its breath for a congressional hearing room.

Context: The $16 Billion Digital Hospital That Never Opened

Let me paint the full picture, because the headline oversimplifies a decade-long saga.

Back in 2018, the Department of Veterans Affairs signed a massive contract with Cerner Corporation—a health IT giant that had built its reputation on the Millennium EHR platform. The goal? Replace VistA, a decades-old legacy system that VA had been running since the 1990s. VistA was functional but ancient, built in an era when floppy disks were cutting-edge. The new system was supposed to bring VA into the modern era: cloud-ready, interoperable, secure.

Then came June 2022. Oracle, Larry Ellison's database empire, completed its acquisition of Cerner for a staggering $28.3 billion. Suddenly, a company known for enterprise software licenses and database contracts owned America's most critical healthcare IT project.

Here's where it gets legally messy. Under the Federal Acquisition Regulation (FAR)—specifically Subpart 42.15—when a contractor undergoes a change of ownership, the contract doesn't automatically transfer. It requires a formal "novation" process, where the new entity must be approved by the contracting officer. The government needs to verify that the new company can actually perform the work. That Oracle inherited this contract through acquisition rather than winning it through competitive bidding? That's not just a technicality—it's a potential legitimacy gap.

The numbers are staggering. The EHRM project has been estimated at over $16 billion in total lifecycle costs. Original projections had full deployment by 2024. We're now in 2025, and only a fraction of VA facilities have gone live. The project has faced multiple pauses, critical GAO reports, and a chorus of clinical complaints—from medication errors to system outages that affected patient care.

But here's the angle that matters most for anyone watching from the crypto world: this is a story about who controls the infrastructure of trust.

The VA EHRM project is, at its core, a centralized system managing sensitive data for millions of veterans. It's the exact opposite of what we're building in Web3. And it's failing—not because decentralization is inherently better, but because the accountability mechanisms that should exist in any system, centralized or not, are breaking down.

From whispered secrets to on-chain shouts—the message from Congress is finally loud: someone must answer for this.

Core: The Legal Architecture of Accountability

Let me walk you through what this hearing actually means from a legal and technical perspective. This isn't just politics—it's a case study in how legacy institutions grapple with accountability gaps that blockchain was designed to solve.

The FAR Framework: Contracts as Code

The Federal Acquisition Regulation governs every aspect of this contract. Think of FAR as the "smart contract" of government procurement—except instead of Solidity, it's written in dense regulatory prose that only a specialized lawyer can parse fluently.

Key provisions at play:

FAR Subpart 42.15 governs contractor changes of ownership. When Oracle acquired Cerner, this provision required formal approval of the contract transfer. The hidden question: did the VA contracting officer conduct sufficient due diligence on Oracle's ability to perform? Or was this a rubber-stamp process that prioritized deal completion over capability assessment?

FAR Clause 52.203-13 requires contractors to maintain a written code of business ethics and conduct, plus an internal control system. This isn't optional—it's a contractual mandate. For Oracle, inheriting Cerner's healthcare compliance culture while integrating it into Oracle's enterprise software culture creates a friction zone where compliance gaps can emerge.

FISMA and HIPAA: The Security Stack

Beyond procurement regulations, Oracle faces a dual security compliance burden:

FISMA (Federal Information Security Modernization Act) requires federal information systems to meet specific security standards. For a system processing veteran health data, this means NIST compliance frameworks, continuous monitoring, and reporting requirements.

HIPAA treats veteran health records as Protected Health Information (PHI). As a Business Associate, Oracle must implement administrative, physical, and technical safeguards. Data breaches must be reported. Security controls must be documented. The penalty structure for HIPAA violations scales with the level of negligence.

Here's what most observers miss: the intersection of FISMA and HIPAA creates a compliance burden that's more than the sum of its parts. You're not just securing data—you're securing it under two overlapping regulatory regimes with different reporting requirements, different audit standards, and different enforcement mechanisms.

The "Technical Exceptionalism" Myth

For decades, defense and VA IT projects operated under an unwritten rule: "government IT is different, so commercial best practices don't apply." This exceptionalism justified monolithic contracts, waterfall development methodologies, and a tolerance for failure that would never be accepted in the private sector.

That era is ending.

Congressional oversight has shifted from post-hoc audits to full-lifecycle intervention. The committee isn't just asking "what went wrong"—they're asking "who made the decisions, when did they know, and what did they do about it?" This tracks with a broader trend I've observed: regulators and legislators are increasingly targeting individual decision-makers rather than just corporate entities.

When the House questioned Silicon Valley Bank executives after the 2023 collapse, they didn't just ask about the bank's risk models. They asked about specific individuals' decisions. The same pattern is emerging here. By summoning Ellison personally—rather than Oracle's government affairs team—the committee signals that they want accountability at the highest level.

The GAO/OIG Shadow

Here's something the Crypto Briefing article doesn't mention, but anyone in Washington will tell you: formal congressional hearings rarely emerge from a vacuum. Behind this scrutiny lies a paper trail of Government Accountability Office (GAO) reports and VA Office of Inspector General (OIG) audits documenting specific failures.

These reports are the ammunition for congressional oversight. They contain the technical details—the missed milestones, the security vulnerabilities, the cost overruns—that committee staffers use to formulate their questions. When Ellison sits before the committee, the questions will be informed by these findings.

Survival is the first layer of value—but accountability is the second, and it's the one that matters when the cameras are rolling.

The Clinical Safety Dimension

Let me go deeper into something that should concern anyone who cares about healthcare technology—not just as a compliance matter, but as a moral imperative.

The VA EHRM project isn't just about data management. It's about patient safety. Reports from facilities that have gone live describe a range of issues: medication errors, system outages during critical procedures, clinicians spending more time navigating the UI than interacting with patients.

This transforms the nature of the congressional inquiry. It's no longer just about contract performance or cost overruns—it's about whether the system is safe for veterans. That's a fundamentally different standard, and it raises the stakes for Oracle considerably.

If the committee finds evidence that patient harm resulted from system failures, the legal exposure expands beyond contract remedies into potential tort liability and, more significantly for Oracle's federal business, potential suspension or debarment under FAR Subpart 9.4.

For a company that relies on federal contracts for billions in annual revenue, debarment would be catastrophic. It's the nuclear option—rarely used, but always looming in the background of any major federal contract dispute.

Contrarian: The Decentralization Blind Spot

Now let me challenge the conventional framing—because there's a deeper issue here that most commentators are missing.

The standard narrative says: "Oracle failed to deliver, Congress is holding them accountable, and that's how oversight should work." But let me ask a different question: why did we trust a single vendor with $16 billion and the health records of millions of veterans in the first place?

This is where my Web3 perspective becomes relevant. The entire premise of blockchain technology is that concentrated control without transparency creates systemic risk. The VA EHRM project is a textbook example of this failure mode—not because the people involved were malicious, but because the architecture of trust was flawed from the start.

Consider what decentralization could have offered:

Data Portability: Veterans' health records aren't owned by the VA or Oracle—they belong to the veterans themselves. A decentralized system could have enabled veterans to control their own data, sharing it with providers as needed without relying on a centralized intermediary.

Interoperability by Design: The VA's interoperability problems stem partly from the monolithic architecture of legacy systems. Blockchain-based health data standards could enable seamless data exchange across providers, reducing the friction that plagues current systems.

Transparent Audit Trails: Smart contracts could encode compliance rules directly into the system, making every access to veteran data auditable and transparent. No more relying on Oracle's internal monitoring—the system itself would enforce accountability.

Community Governance: Instead of a single corporate entity making decisions about system architecture and priorities, a decentralized governance model could involve veterans, clinicians, and other stakeholders in ongoing system refinement.

Now, I'm not naive enough to suggest that blockchain is a silver bullet for government IT. The technical challenges of scaling decentralized systems to handle millions of records are real. The regulatory frameworks for decentralized health data don't exist yet. And the inertia of legacy systems is formidable.

But here's my contrarian point: the very accountability deficit that Congress is investigating is a feature of centralized systems, not a bug that can be fixed through better oversight. You can add more reporting requirements, more audits, more committee hearings—but as long as a single entity controls the infrastructure, you'll have the same fundamental risk.

Chaos isn't a bug; it's the protocol—and the chaos we're seeing in government IT is the protocol of centralized control.

The committee's approach is necessary but insufficient. It's treating the symptoms—specific failures, specific decisions, specific individuals—while leaving the underlying architecture unchallenged.

Takeaway: What This Means for the Future

Let me bring this back to something tangible for anyone building in Web3, because this story isn't just about Oracle or the VA. It's about the future of digital infrastructure.

The Oracle hearing represents a watershed moment in how governments think about technology accountability. The old model—hire a mega-vendor, hand them billions, trust them to deliver—is breaking down. Not because vendors are uniquely evil, but because the complexity of modern systems exceeds the capacity of any single organization to manage without transparent, distributed accountability mechanisms.

For Web3 builders, this is both a cautionary tale and an opportunity:

The Cautionary Tale: Decentralization doesn't automatically solve accountability. DAOs have governance failures. Smart contracts have bugs. Communities can be captured by whales. If we're going to build alternatives to legacy systems, we need to design accountability mechanisms into our protocols—not assume they'll emerge organically.

The Opportunity: As governments grapple with mega-contract failures, the case for alternative architectures becomes stronger. Not because blockchain is magic, but because it offers structural solutions to the structural problems that centralized systems face.

The takeaway isn't that blockchain will replace government IT systems tomorrow. It's that the philosophical case for decentralization—transparency, user ownership, distributed governance—is being validated by the failures of its opposite.

Walls crumble when the party truly begins—and Washington just heard the first crack.

Three years of whispers built the loudest room—now the room is a congressional hearing chamber.

The question isn't whether Larry Ellison will face consequences. It's whether we'll learn the deeper lesson: that trust in digital infrastructure can't be purchased with billion-dollar contracts or enforced through congressional subpoenas alone. It has to be architected into the system itself.

That's the lesson I carried from Prague's 2017 chaos, from DeFi Summer's aftermath, from the NFT party crash. And it's the lesson that will define the next decade of digital infrastructure—whether Washington is ready for it or not.

The network breathes in Prague, pulses in Ethereum, and waits for the day when every system—public or private, centralized or decentralized—answers to the people it serves.