Menu
Browse

Cyber Incident Victim: Aesto Health

Date:

Dec 2021

Location:

United States of America

Summary

Aesto Health experienced a data security incident involving unauthorized access to its internal IT systems over an extended period, impacting 17,400 patients of Osceola Medical Center. The breach resulted in the copying of files from a backup storage device, compromising names, dates of birth, radiology report findings, and associated physician names. The organization confirmed its own medical records and data systems remained secure and unaffected, with no evidence requiring further action by impacted individuals. Discovery occurred following IT operation disruptions, prompting an investigation that identified the unauthorized system access and exfiltration of sensitive patient information.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

Aesto Health experienced a data security incident impacting its internal IT systems, first detected on March 8, 2022, when the company observed disruptions in its IT operations. The investigation confirmed on March 22 that patient information was involved, tracing unauthorized access to its systems between December 25, 2020, and March 8, 2022. During this period, an attacker copied files from a backup storage device containing radiology reports for Osceola Medical Center (OMC) patients, for whom Aesto Health served as a business associate. The compromised records included patient names, dates of birth, radiology report findings, and associated physician names. Aesto Health clarified that OMC’s own data systems and medical records remained secure and were not directly accessed during the breach. The incident affected 17,400 OMC patients, with notification letters mailed starting May 20, 2022.

Cyber Incident Image

Aesto Health’s response emphasized containment and transparency, stating no further patient action was required due to the nature of the exposed data. The company did not disclose specific technical remediation steps but affirmed it took the incident seriously and regretted any patient concerns. Law enforcement involvement was not mentioned in available reports, nor were details provided about whether ransomware or extortion attempts accompanied the data exfiltration. The breach timeline overlapped with a separate cyber event at Aon PLC, though no connection between the incidents was indicated. OMC’s operations and patient care systems remained unaffected, as the compromise was isolated to Aesto Health’s backup storage infrastructure. No misuse of the copied radiology data was confirmed at the time of reporting.

Sources
Sources available to members
1 source