news.mlab.sh
Back to the feed
data-breach

Health data of more than 9.5 million people leaked from Aesto record system

High
Summary

Aesto, a healthcare data company, suffered a cyberattack that exposed the sensitive health information of over 9.5 million people. The breach involved stolen data including names, Social Security numbers, and medical records, impacting numerous healthcare organizations and highlighting a concerning trend of data leaks within the healthcare industry.

Aesto, a healthcare data company based in Birmingham, Alabama, recently informed federal regulators about a significant cyberattack that compromised the health information of more than 9.5 million individuals. The company initially alerted customers in June, but has now revealed the full scope of the breach. The stolen data included sensitive details such as names, Social Security numbers, medical information, driver’s license numbers, and financial account details.

The attack occurred between December 2nd and December 18th, with hackers gaining access to Aesto’s Amazon Web Services infrastructure. Aesto provides data migration and archiving services to medical facilities undergoing technology upgrades or EHR vendor transitions, supporting healthcare groups being acquired by other companies.

At least 30 healthcare organizations were affected by the breach, including Together Women’s Health in Texas and California. Aesto filed breach notices in several states on behalf of its customers.

No hacking group has publicly claimed responsibility for the attack, and Aesto declined to comment. This incident follows similar breaches at other healthcare data firms, including Baylor Genetics and CareCloud, further demonstrating a growing vulnerability within the sector.

Park Dental Partners also reported a cyberattack, prompting them to engage cybersecurity experts and report the incident to the SEC.

Read the full article at The Record