Aesto LLC, operating as Aesto Health, disclosed the breach in a notification on its website on June 24, stating that "a limited portion" of its Amazon Web Services infrastructure had been compromised. In a filing with the U.S. Department of Health and Human Services, the company said 9,540,683 individuals were affected. The exposed data includes full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer identification numbers, and Social Security numbers.
The incident indirectly impacts 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women's Health, according to HIPAA Journal. Aesto began notifying impacted individuals on August 21, offering 24-month identity theft protection and credit monitoring through Experian.
In a separate incident, Novocure, a global oncology company with over 1,300 employees, disclosed in an SEC filing that unauthorized access to its systems in mid-August exposed the records of more than 1,400 U.S. cancer patients. The company said the accessed patient records included ID numbers but not names or other identifying data for most. For fewer than 50 patients in the western U.S., identifying information and contact details for healthcare providers were exposed. Employee contact information, including job titles and phone numbers, was also accessed. Novocure stated that no medical treatment devices were accessed, its ability to operate has not been compromised, and all systems are fully functional.
Both breaches add to a recent surge in cyberattacks targeting healthcare companies. Last month, healthcare software firm Unlimited Technology Systems disclosed a breach affecting more than 3.8 million people, while health IT company CareCloud reported a March breach impacting 3.7 million individuals. Hospital operator Nutex and pharmaceutical distributor McKesson have also reported incidents this year.