Health data of more than 9.5 million people leaked from Aesto record system
Health data firm Aesto reported a breach affecting over 9.5 million people after hackers accessed its AWS infrastructure between December 2 and 18.
Alabama-based healthcare data company Aesto notified the Department of Health and Human Services that more than 9.5 million people had sensitive information leaked in a December cyberattack, after previously warning customers in June without disclosing scope. Attackers broke into the company's Amazon Web Services infrastructure between December 2 and December 18, stealing names, Social Security numbers, medical information, driver's license numbers, financial account numbers, and health insurance data. Aesto provides data migration and archiving services for medical facilities, and at least 30 healthcare organizations were affected, with breach notices filed for customers including Together Women's Health. Related healthcare incidents disclosed this year include Baylor Genetics (2.8 million people), CareCloud (3.7 million), and recent attacks at McKesson, Nutex, Paylogix, and Park Dental Partners.
- Data stolen includes SSNs, medical and health insurance information, driver's license and financial account numbers
- At least 30 healthcare organizations affected; no group has claimed the attack
- Follows a string of healthcare-sector breaches: Baylor Genetics 2.8M, CareCloud 3.7M, plus McKesson, Nutex, Paylogix, Park Dental Partners
Full article400 words · extracted from therecord.media · click to collapse
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December. The Birmingham, Alabama-based company previously warned customers about the attack in June but had not shared information about the scope. On TKDAY, it notified the Department of Health and Human Services that millions were impacted by the data breach. The stolen data includes names, Social Security numbers, medical information, driver’s license numbers, financial account numbers, health insurance data and more. In its June statement, the company said an investigation revealed that hackers broke into its Amazon Web Services infrastructure between December 2 and December 18, stealing troves of information related to patients of its customers. Aesto provides data migration and archiving services to medical facilities upgrading their technology or switching electronic health record vendors and supports healthcare groups purchased by other companies. At least 30 healthcare organizations were affected by the Aesto breach. Aesto filed breach notices in several states on behalf of its customers, including Together Women's Health in Texas and California. No hacking group has publicly taken credit for the attack on Aesto and the company did not respond to requests for comment. Millions of people have had sensitive information leaked through cyberattacks on healthcare data firms this year. Baylor Genetics also told federal regulators this week that more than 2.8 million people had medical testing information, laboratory test results and more stolen during a cyber incident in June. Another 3.7 million people were impacted by a March cybersecurity incident involving electronic health records giant CareCloud. Healthcare companies McKesson, Nutex, Paylogix all announced cyberattacks over the last two weeks that involved patient and customer data. Park Dental Partners warned the Securities and Exchange Commission (SEC) on Tuesday night of a cyberattack last week that forced them to initiate incident response protocols and hire outside cybersecurity experts. While the attack did not impact the operations of the company, it decided to report the incident to the SEC “due to the possible access of patient data.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/health-data-aesto-cyberattack-leak