HIPAA Pulse by Patient Protect logo

HIPAA Pulse by Patient Protect

Archives
Log in
September 2, 2026

HIPAA Pulse | Sept 2nd

HIPAA Pulse — September 2, 2026
A vendor that archives legacy healthcare data reported a breach affecting 9.5 million people after a five-month review. CareCloud's breach count jumped from roughly 350,000 to 3.7 million. ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌
Patient Protect
HIPAA Pulse

HIPAA PULSE

September 2, 2026  ·  Bi-Weekly Briefing

9.5 Million People at an Archive Vendor, and CareCloud Jumps to 3.7M

A vendor built around healthcare-data migration and legacy archiving got breached. It took five months to confirm PHI may have been accessed or acquired. The number is 9.5 million people.

Aesto Health stores legacy patient records for other healthcare organizations — the data left behind when a practice switches systems or gets acquired. That is the risk we have been circling all summer: old data does not stop being a liability just because nobody is using it anymore.

Also this window: CareCloud's count moved again — from an early roughly 350,000-person total to 3.7 million on the HHS tracker.

9.5M

affected by the breach at Aesto Health, per the HHS OCR breach portal. The company detected the intrusion in December 2025 and didn't confirm what information may have been accessed or acquired until May 2026 — the largest figure we've reported in this newsletter apart from DentaQuest.

Since the last issue, August 19

2

named stories verified this window, both with real revision history

5 mo.

Aesto Health's gap between discovery and confirming what may have been accessed

11x

CareCloud's growth from its first reported figure to the current HHS-tracker count

No historical mega-breaches resurfaced with fresh dates this window — the check we run every issue came back clean this time.

Open the live dashboard Free · No account · Updated nightly

Breach of Note: Aesto Health

HHS OCR portal  ·  9,540,683 affected  ·  Hacking/IT Incident  ·  Business Associate

Aesto, LLC, doing business as Aesto Health, is a Birmingham, Alabama company that provides data migration, legacy archiving, and EHR-exchange services to healthcare organizations. Its business is holding onto patient records for other companies, often the data left behind when a practice switches systems or gets acquired. The company detected unauthorized access to part of its AWS infrastructure on or around December 18, 2025. Investigators later narrowed the intrusion to December 2–18.

Aesto did not confirm until May 26, 2026 that PHI may have been accessed or acquired — more than five months after discovery, following a forensic investigation and manual document review. The company posted a public notice June 24 describing "a limited portion" of its systems as affected. The HHS OCR listing adds the scale: 9,540,683 individuals, across two dozen-plus of Aesto's healthcare provider clients in multiple states. The potentially involved information includes names, dates of birth, Social Security numbers for a limited subset, driver's license and other government ID numbers, financial account numbers, taxpayer ID numbers, and medical and health insurance information. No group has publicly claimed responsibility.

The uncomfortable part is what Aesto does for a living. It holds old healthcare data for other organizations — records from system migrations, closed practices, and acquisitions. That data may be out of sight for the original provider. It is not out of reach for an attacker. Old records do not stop being risky because nobody opens them every day.

Worth asking: If your practice has ever migrated EHR systems, closed a location, or been acquired, do you know where the old records ended up, and who's holding them now? Does your BAA inventory include archival and migration vendors, or only the systems you actively use today? If a vendor holding your old data got breached, would you even know to ask? Run the free assessment.

CareCloud is now 3.7 million people, not 350,000

CareCloud's breach count has moved again. The first public figure was roughly 350,000 people. HHS later showed 3,371,508. Now independent reporting from SecurityWeek and Malwarebytes puts the count at 3,756,469. We saw the larger number earlier and held it back because we could not verify it. That was the right call: the number was real, but the public record had not caught up yet. The underlying incident hasn't changed — unauthorized access to an AWS environment between March 10 and 16, no group has claimed responsibility. Only the reported scope has moved, three times, in about six weeks.

The Privacy Rule's August target has now passed, too

Last issue, we flagged a second HIPAA rule targeted for August 2026: a Privacy Rule update covering faster patient record access and expanded caregiver involvement, distinct from the Security Rule overhaul already pushed to 2027. The most recent status we found still showed it unpublished. We found no report of it landing before the month closed. Agency timelines aren't binding, and this rule could still arrive any week — but for now, add it to the same pile as the Security Rule: targeted, not delivered.

30-minute system check

Five items, each tied to something above.

1.

Find out where your old records actually went. If your practice has migrated EHR systems, closed a location, or absorbed another practice, someone is holding that old data right now. Confirm who, and whether they're still under a current BAA.

2.

Add archival and migration vendors to your BAA inventory. These are easy to forget because they're not part of daily operations. Aesto's clients found that out the hard way. If a vendor holds your old data, they belong on the same list as the ones you use every day.

3.

When a vendor breach makes headlines, wait for the filing before you repeat a number. CareCloud's public count moved three times in six weeks. The early estimate, state filings, and current federal tracker are three different things — check which one you're citing.

4.

Ask any archival or storage vendor how long they retain data after a client relationship ends. "Indefinitely, unless someone asks" should not be an acceptable answer.

5.

Keep both HIPAA rules on your calendar, not just the one that's further along. The Security Rule slipped to 2027. The Privacy Rule just missed its own August target. Neither timeline is final, and both could move again without much notice.

The free HIPAA Risk Assessment inventories your vendors, BAAs, and data flows in about 30 minutes. No account needed.

Run the free assessment Free · No account · 30 minutes
 

A word from Patient Protect, who pays for this newsletter to exist

Your vendors are your attack surface. Track them like it.

Vendor inventory with offboarding and data-disposition tracking. BAA lifecycle alerts, including notification-deadline terms. Continuous risk analysis. $39/month, no contracts, 14-day free trial.

Start free trial See pricing

Worth reading elsewhere

  Madera Community Hospital breach filing: 150,810 individuals

A risk analysis scoped only to system availability won't catch confidentiality threats like data removal. Source of record: HHS OCR.

  Brown Health Medical Group breach filing: 311,760 individuals

Server-level ePHI access puts the Security Rule's access-control and audit-logging requirements directly in scope. Source of record: HHS OCR.

The same thing keeps happening. A vendor holds old data. A breach happens. Months pass before the scope is clear. Then providers are left figuring out which patients are affected by systems they may not even use anymore. Aesto isn't a new story so much as a very large version of a familiar one.

Next Pulse drops September 16.

Editorial coverage at patient-protect.com/hipaa-pulse. This briefing comes from Patient Protect.

Patient Protect

Chicago, IL  ·  patient-protect.com  ·  HIPAA Pulse

Instagram LinkedIn X

Aesto Health's figure reflects the HHS OCR breach portal listing. CareCloud's current figure (3,756,469) reflects independent reporting from SecurityWeek and Malwarebytes, both citing the HHS breach tracker; the earlier 3,371,508 figure, confirmed accurate by Patient Protect's own HIPAA Response team, is superseded by this later revision. Madera Community Hospital and Brown Health Medical Group figures reflect HHS OCR filings as reported by Patient Protect's HIPAA Response.

You're receiving HIPAA Pulse because you subscribed at patient-protect.com. Manage email preferences  ·  Unsubscribe  ·  Privacy Policy

© 2026 Patient Protect LLC. All rights reserved.

Don't miss what's next. Subscribe to HIPAA Pulse by Patient Protect:
← Newer HIPAA Pulse | Sept 16 Older → HIPAA Pulse | August 19th
Instagram
Twitter
LinkedIn
YouTube