Aesto Health breach exposes 9.5 million patients, adding to wave of healthcare cyberattacks

The December 2025 intrusion, confirmed in May, indirectly affects 29 healthcare providers; Novocure separately reports 1,400 patients impacted in August attack

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
Healthtech software provider Aesto Health has disclosed that a data breach discovered in December 2025 affects more than 9.5 million individuals, making it one of the largest healthcare-related breaches this year. The company, which helps healthcare organizations migrate and archive patient data, said the intrusion occurred between December 2 and December 18, 2025, and was confirmed on May 26 following a forensic investigation. Separately, oncology company Novocure reported that a mid-August cyberattack exposed data from over 1,400 U.S. cancer patients, though the company said no medical devices were accessed and operations remain unaffected.

Aesto LLC, operating as Aesto Health, disclosed the breach in a notification on its website on June 24, stating that "a limited portion" of its Amazon Web Services infrastructure had been compromised. In a filing with the U.S. Department of Health and Human Services, the company said 9,540,683 individuals were affected. The exposed data includes full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer identification numbers, and Social Security numbers.

The incident indirectly impacts 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women's Health, according to HIPAA Journal. Aesto began notifying impacted individuals on August 21, offering 24-month identity theft protection and credit monitoring through Experian.

In a separate incident, Novocure, a global oncology company with over 1,300 employees, disclosed in an SEC filing that unauthorized access to its systems in mid-August exposed the records of more than 1,400 U.S. cancer patients. The company said the accessed patient records included ID numbers but not names or other identifying data for most. For fewer than 50 patients in the western U.S., identifying information and contact details for healthcare providers were exposed. Employee contact information, including job titles and phone numbers, was also accessed. Novocure stated that no medical treatment devices were accessed, its ability to operate has not been compromised, and all systems are fully functional.

Both breaches add to a recent surge in cyberattacks targeting healthcare companies. Last month, healthcare software firm Unlimited Technology Systems disclosed a breach affecting more than 3.8 million people, while health IT company CareCloud reported a March breach impacting 3.7 million individuals. Hospital operator Nutex and pharmaceutical distributor McKesson have also reported incidents this year.

§

Analysis

Why This Matters

  • Patients face long-term identity theft risk: The exposure of Social Security numbers and medical information in the Aesto breach makes affected individuals vulnerable to fraud and medical identity theft.
  • Healthcare sector remains a prime target: The volume of patient data held by third-party vendors creates cascading risks. A single breach at a software provider can expose millions across multiple healthcare organizations.
  • Regulatory scrutiny likely to intensify: Both incidents will trigger investigations under HIPAA and state breach notification laws, and could lead to fines or class-action lawsuits.

Background

Healthcare data breaches have become increasingly common, with threat actors targeting both healthcare providers and the technology vendors that support them. Third-party software companies that handle patient data for multiple healthcare organizations present a particularly attractive target, as a single intrusion can expose records from dozens of providers. Aesto Health specializes in data migration and archiving for electronic health record systems. Novocure is known for its Tumor Treating Fields (TTFields) therapy, a non-invasive cancer treatment.

Key Perspectives

Affected patients and providers: Face disruption, potential fraud, and the burden of monitoring credit and medical records. Healthcare providers must notify patients and may face reputational damage. Aesto Health and Novocure: Both companies emphasize that operations were not affected and that they are cooperating with investigations and notification requirements. Aesto has offered credit monitoring. Cybersecurity experts and regulators: View healthcare as critically underprotected. The U.S. Department of Health and Human Services and state attorneys general are likely to investigate whether adequate safeguards were in place.

What to Watch

  • Whether Aesto Health faces regulatory fines or class-action litigation given the scale of the breach.
  • Further disclosures from Novocure on whether attacker demands were made or how the network was compromised.
  • Whether the wave of healthcare breaches prompts new federal cybersecurity requirements for health-tech vendors.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.