Medical device
Image: Navy Medicine / Unsplash

Health data of more than 9.5 million people leaked from Aesto record system

The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December. 

The Birmingham, Alabama-based company previously warned customers about the attack in June but had not shared information about the scope. On TKDAY, it notified the Department of Health and Human Services that millions were impacted by the data breach. 

The stolen data includes names, Social Security numbers, medical information, driver’s license numbers, financial account numbers, health insurance data and more. 

In its June statement, the company said an investigation revealed that hackers broke into its Amazon Web Services infrastructure between December 2 and December 18, stealing troves of information related to patients of its customers. 

Aesto provides data migration and archiving services to medical facilities upgrading their technology or switching electronic health record vendors and supports healthcare groups purchased by other companies. At least 30 healthcare organizations were affected by the Aesto breach. 

Aesto filed breach notices in several states on behalf of its customers, including Together Women's Health in Texas and California

No hacking group has publicly taken credit for the attack on Aesto and the company did not respond to requests for comment. 

Millions of people have had sensitive information leaked through cyberattacks on healthcare data firms this year. Baylor Genetics also told federal regulators this week that more than 2.8 million people had medical testing information, laboratory test results and more stolen during a cyber incident in June.

Another 3.7 million people were impacted by a March cybersecurity incident involving electronic health records giant CareCloud. 

Healthcare companies McKesson, Nutex, Paylogix all announced cyberattacks over the last two weeks that involved patient and customer data. 

Park Dental Partners warned the Securities and Exchange Commission (SEC) on Tuesday night of a cyberattack last week that forced them to initiate incident response protocols and hire outside cybersecurity experts. 

While the attack did not impact the operations of the company, it decided to report the incident to the SEC “due to the possible access of patient data.”

Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.