Back to all lessons
Awareness Lessons
last month

9.5 Million Patients Exposed in Aesto Health Software Breach

A months-long unauthorized access incident at Aesto Health — a third-party healthcare software provider — exposed sensitive data for over 9.5 million patients across 29 healthcare organizations, highlighting the cascading risk of supply chain vulnerabilities in healthcare IT. The breach persisted undetected from December 2025 to May 2026, suggesting critical failures in access controls and continuous monitoring. Because the compromised data includes Social Security numbers, dates of birth, and medical records, affected individuals face compounded risks of identity theft and medical fraud. This incident underscores that healthcare organizations are only as secure as their third-party vendors, making vendor risk management a patient safety issue, not just an IT concern.

Tactical Insight

Immediate actions

  • Conduct an urgent audit of all third-party vendor access permissions and revoke any unnecessary or overprivileged credentials.
  • Deploy real-time anomaly detection and alerting on systems containing Protected Health Information (PHI) to identify unauthorized access early.
  • Notify affected patients promptly and provide identity theft monitoring services in compliance with HIPAA Breach Notification Rule timelines.

Long-term improvements

  • Implement a formal Third-Party Risk Management (TPRM) program that requires vendors to meet defined security baselines before handling patient data.
  • Enforce least-privilege access controls and multi-factor authentication (MFA) for all vendor and internal accounts accessing sensitive health records.
  • Establish contractual security requirements with healthcare software vendors, including mandatory breach notification windows and regular independent audits.

Detection measures

  • Deploy a Security Information and Event Management (SIEM) solution with use cases tuned for healthcare data exfiltration patterns.
  • Schedule quarterly penetration tests and continuous vulnerability scanning across all systems that store or process PHI.
  • Require vendors to provide SOC 2 Type II reports or equivalent attestations annually to validate their security posture.