A company most people have never heard of just told federal regulators it leaked sensitive information on more than 9.5 million people. Aesto, a healthcare data firm in Birmingham, Alabama, says attackers were inside its Amazon Web Services environment from December 2 to December 18 last year. The stolen data includes names, Social Security numbers, driver’s license numbers, financial account numbers, health insurance details and medical information, according to The Record.
At least 30 healthcare organizations were affected. Not one of them was breached. Their vendor was.
What Aesto actually does, and why that’s the point
Aesto handles data migration and archiving. When a medical or dental practice switches electronic health record systems, or gets acquired by a larger group, somebody has to move the old chart data and keep an archived copy of it. That is the job. It is boring, necessary work, and it means a third party ends up holding a full copy of your patient records.
That is the part small practices consistently underestimate. You vetted your EHR. You probably never thought hard about the company that moved your data into it three years ago, or the archive of your old system that is still sitting in someone’s cloud storage because nobody ever said “you can delete that now.”
Aesto told customers about the attack back in June. The scope, 9.5 million people, only went to the Department of Health and Human Services this week. That gap is normal in these cases and it is exactly why waiting for your vendor to tell you the whole story is a bad plan.
This is not a healthcare-only problem
Swap “EHR migration” for any of these and the picture is identical. Your old payroll provider. The bookkeeping firm that has five years of client files in a shared cloud folder. The marketing agency with admin access to your website and your customer list. The IT company you fired in 2023 that may still have a backup image of your server. The scanning service that digitized your paper files.
Every one of those relationships creates a copy of your data somewhere you do not control and cannot monitor. When that vendor gets hit, the notification letters go out with your name on them, because your clients gave their information to you, not to your vendor’s vendor.
The healthcare notification news this week wasn’t a one-off either. Baylor Genetics reported more than 2.8 million people affected by a June incident. CareCloud reported 3.7 million from March. Park Dental Partners disclosed an attack to the SEC on Tuesday. The pattern is consistent: the aggregators get hit, and dozens of small practices absorb the fallout.
What to do this week
Five things, in order, and none of them require a project plan.
1. Write down every vendor that holds or can reach your client data. Not a formal register. A list. EHR or practice management, payroll, billing, bookkeeping, backup provider, website host, e-commerce platform, document scanning, anyone with remote access to your machines. Most small businesses find 12 to 20 and are surprised by half of them.
2. Find the ones that should have been shut off. Old systems, finished migrations, former providers. For each one, send a written request asking them to confirm in writing that your data has been deleted and to tell you the date. Keep the reply. Data that no longer exists cannot be stolen, and this is the single highest-value item on the list.
3. Check your agreements for breach notification timing. If you are a healthcare practice, a business associate agreement should require the vendor to notify you promptly, and HIPAA gives you 60 days from discovery to notify affected individuals. If your contract is silent on notification, that is the thing to fix at renewal. Outside healthcare, look at your cyber insurance policy: many require notification to the carrier within days, not weeks.
4. Ask the ones you still use two specific questions. Do you require MFA on all administrative access to the systems holding our data, and can you provide a recent third-party security assessment or SOC 2 report? Vague reassurance is an answer. A bad one.
5. Confirm you hold your own copy. If your vendor is your only archive, their bad day becomes your permanent data loss. Independent backups you control (we set these up and test the restores) are the difference between an inconvenience and a business you can’t operate.
The honest part
You cannot audit your way to safety here. You are not going to inspect a cloud vendor’s infrastructure, and pretending otherwise wastes time. What you can do is shrink the number of companies holding your data, know which ones they are, and have your own copy of everything that matters. That is achievable in an afternoon and it is where most of the risk reduction lives.
If you’re not sure who is holding your client data right now, that inventory is a good place to start and we can build it with you. Book a free 15-minute consult.