Healthcare Data Firm Aesto Exposes 9.5 Million Records in Major Breach
A significant cyberattack on healthcare data company **Aesto** has led to the compromise of sensitive information for over 9.5 million individuals. The breach, which occurred in December, exposed a wide range of personal and medical data, highlighting persistent vulnerabilities within the healthcare sector's digital infrastructure.
Healthcare data migration and archiving provider **Aesto** has disclosed a major data breach impacting more than 9.5 million individuals. The Birmingham, Alabama-based company confirmed to federal regulators this week that a cyberattack, which took place in December, resulted in the theft of extensive sensitive information.
**Aesto** first alerted customers to the incident in June but only recently provided details on the full scope of the breach to the Department of Health and Human Services.
### Data Compromised
The stolen data is highly sensitive and includes:
* Names
* Social Security numbers
* Medical information
* Driverβs license numbers
* Financial account numbers
* Health insurance data
### Attack Vector and Impact
According to **Aesto**'s June statement, an investigation revealed that hackers infiltrated its **Amazon Web Services** infrastructure between December 2 and December 18. During this period, they exfiltrated troves of patient-related information belonging to **Aesto**'s clients. The company, which assists medical facilities with technology upgrades, electronic health record vendor switches, and acquisitions, confirmed that at least 30 healthcare organizations were affected.
**Aesto** has filed breach notices in several states on behalf of its customers, including **Together Women's Health** in Texas and various entities in California.
### Broader Trends in Healthcare Breaches
This incident is part of a troubling trend of cyberattacks targeting healthcare data firms this year. Just this week, **Baylor Genetics** informed federal regulators that over 2.8 million people had their medical testing information and laboratory test results stolen in a June cyber incident.
Similarly, **CareCloud**, an electronic health records giant, reported a March cybersecurity incident affecting 3.7 million individuals. Other recent announcements of cyberattacks involving patient and customer data include **McKesson**, **Nutex**, and **Paylogix**.
### SEC Notification by Park Dental Partners
Adding to the growing list, **Park Dental Partners** recently warned the **Securities and Exchange Commission (SEC)** of a cyberattack that occurred last week. While the attack did not disrupt company operations, **Park Dental Partners** initiated incident response protocols and engaged external cybersecurity experts. The company reported the incident to the **SEC** "due to the possible access of patient data," underscoring the severe regulatory and reputational risks associated with such breaches.