$ techbeacon▋
Threats

Millions of Health Records Exposed in Aesto Cyberattack, Regulators Notified

Millions of Health Records Exposed in Aesto Cyberattack, Regulators Notified

Aesto, a company that manages health‑care data for providers and insurers, disclosed to federal regulators that a cyberattack in December resulted in the exposure of sensitive information belonging to more than 9.5 million individuals.

The breach, which was first reported by The Record, involved unauthorized access to Aesto's record‑keeping system. The company said the intrusion allowed attackers to view and potentially extract personal health information, though it did not specify the exact types of data compromised.

Health‑care firms are subject to strict privacy rules under the Health Insurance Portability and Accountability Act (HIPAA), and a breach of this scale typically triggers mandatory notifications to both regulators and affected individuals. Aesto confirmed that it has begun the required notification process, but it has not yet released a timeline for when those notices will be sent.

Cybersecurity experts note that attacks on health‑care data repositories have risen sharply in recent years, as medical records are valuable on the black market for identity theft, fraud, and extortion. The scale of Aesto's incident—affecting nearly ten million records—places it among the largest health‑care data exposures in the United States.

Federal agencies, including the Department of Health and Human Services' Office for Civil Rights, are expected to investigate the breach to determine whether Aesto complied with security standards and reporting obligations. The outcome could influence future enforcement actions and may prompt tighter regulatory scrutiny of third‑party data processors.

In the meantime, consumer advocacy groups are urging individuals whose information may have been compromised to monitor credit reports and be alert for suspicious activity. Aesto has pledged to bolster its security infrastructure and to cooperate fully with investigators, though it has not disclosed specific remediation steps at this time.

Source: The Record
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related