Health data of more than 9.5 million people leaked from Aesto record system
Healthcare data processor Aesto disclosed a breach affecting 9.5 million records — a scale that should prompt European enterprises to reassess vendor risk management for any third party handling sensitive health or employee data.
Summary written by editorial AI · Source link below
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.
Editorial Analysis
Framed for the Compliance & GRC desk
A breach of this scale at a health data processor raises questions about vendor due diligence, data-processing agreements, and breach notification timelines — directly relevant to GDPR Article 28 obligations.
Audit data-processing agreements with health-sector vendors for breach notification timelines and verify that Article 28 GDPR requirements are contractually enforced.
A 9.5-million-record health data breach highlights the liability exposure from third-party data processors.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at The Record in a new tab.
More from the Security Desk
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted2d
- IDScan sued over alleged data breach affecting 153 million drivers3d
- Your Employee’s Password Appeared in an Infostealer Log. Now What?4d
- US and Canadian court data exposed in Thomson Reuters breach4d
- The Agentic SOC – From AI Theater to Real Defense1 Sept