Not broken according to the response to that paper:
the conclusions drawn by this paper with regard to CryptDB's guarantees for medical applications are incorrect: had the guidelines been followed, none of the claimed attacks would have been possible. [1]
E.g. googling i found http://cs.brown.edu/people/seny/pubs/edb.pdf