
Share
Two massive healthcare data breaches this summer exposed millions of patient records stored on cloud platforms. The real culprit isn't the cloud itself, experts say, but the doors left unlocked inside it.
Think about the last time you handed over your driver's license, your insurance card, or your medical history to a doctor's office. You probably assumed that information would stay put, protected behind locked doors and careful hands. Increasingly, that assumption is wrong, not because the doors don't exist, but because too many of them are left unlocked.
Two recent breaches have made that risk concrete for millions of people. CareCloud, a developer of electronic health record, billing, and documentation technology, confirmed last month that a hacker accessed one of its Amazon Web Services environments. According to the HHS Office for Civil Rights breach portal, the incident compromised the electronic health information of more than 3.7 million individuals.
An even larger breach hit Aesto Health, a data migration and management company that reported to HHS in July that a security incident, which actually occurred back in December, affected a staggering 9.5 million individuals. Medtronic and McKesson round out a rough summer for healthcare data security, with both companies reporting breaches tied to Salesforce and, in McKesson's case, the AI data cloud Snowflake. The ShinyHunters group has claimed responsibility for both, reportedly using "vishing," or voice phishing, to trick employees into handing over login credentials.
These aren't abstract statistics. Each number represents a real person whose Social Security number, birth date, or diagnosis history is now sitting somewhere it shouldn't be.
It's tempting to call these "cloud breaches" and leave it there, as though the cloud itself were some leaky vault. Pete Basica, founder and chairman of 360, an AI-enabled digital therapeutics and remote patient monitoring platform, pushes back hard on that framing.
"Based on the information made public, there is no evidence that Amazon Web Services itself was breached," Basica told Healthcare IT News. "Aesto reported that an unauthorized party gained access to a portion of Aesto's infrastructure hosted on AWS. Those are two very different things."
Here's a useful analogy. AWS is like the landlord of a massive office building. It secures the foundation, the walls, the elevators. But what happens inside each tenant's office, who gets a key, which files sit in an unlocked cabinet, whether the alarm system actually works, that's on the tenant. In this case, the tenant is the healthcare tech company, and the "office" holds millions of patient files.
"The name of the cloud provider is not a security strategy," Basica said. "Neither is a certification or an annual security review." That's a pointed jab, given that Aesto's own website touts what it calls gold standard security certifications. Certifications matter, but they're a snapshot in time, not a guarantee against tomorrow's phishing email.

Basica flagged real unanswered questions about the Aesto incident. Why could a single point of entry reach information belonging to more than 9.5 million people? Why didn't monitoring systems catch the activity before the data actually left the building?
Those questions point to a deeper structural issue: the concentration of patient data in the hands of a small number of vendors. "When millions of patient records are placed in one vendor's environment, the failure of one company can affect patients across many unrelated healthcare organizations," Basica said. "That is what makes this breach so serious."
Patients affected by the Aesto breach may never have heard of the company. They didn't choose it, didn't sign anything with it, and likely have no idea their provider even uses it. That's the uncomfortable nature of today's healthcare data ecosystem: your information travels through vendors you'll never meet, protected by security practices you have no way to evaluate.
And the damage compounds over time. "It is reasonable to believe that some of the information involved in this breach duplicates information stolen in earlier breaches," Basica explained. Criminals don't just want fresh data, they want to cross-reference it. An address confirmed here, an insurance ID matched there, a diagnosis added to the pile: each new leak makes an existing stolen identity more complete and more valuable on criminal markets. Unlike a stolen credit card, which can be canceled in minutes, a Social Security number or a medical diagnosis follows a person for life.
So what actually stops a breach from becoming a catastrophe? According to Basica, it comes down to a handful of principles working together: security has to be built into the system's architecture from the start, not bolted on after the fact. Access needs to be limited so that no single compromised account can wander freely across every database. Healthcare clients hosted on a shared platform need to be walled off from one another, so a breach affecting one doesn't cascade into all. And unusual activity, someone pulling far more data than normal, moving between systems they've never touched before, needs to trigger alarms immediately, not after the fact.
Encryption alone won't save you here, Basica cautioned. If stolen credentials are authorized to decrypt information, the system will hand over readable patient records because it believes the attacker is a legitimate user. It's the digital equivalent of a thief using a stolen key, the lock did its job, but the key shouldn't have worked in the first place.
Every one of these breaches started the same way: stolen passwords, an unpatched application, a misconfigured storage bucket, or a vulnerable third-party connection. None of that is unique to the cloud. What the cloud does, when poorly configured, is scale the consequences. A single compromised account with broad permissions can reach across multiple databases and storage systems, turning what should be a contained incident into a breach touching millions.
"Every healthcare technology company entrusted with patient information must design its systems with the expectation that someone will eventually attempt to get through the first door," Basica said. The real test isn't whether that first door holds. It's whether the second door, and the third, keep the attacker from ever reaching the patients on the other side. For the millions of people whose records were exposed this summer, that test came too late.
Tags
Original Sources
Cloud data breaches and stopping data exfiltration
↗ https://www.healthcareitnews.com/news/cloud-data-breaches-and-stopping-data-exfiltration
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
4 September 2026
40 articles
Related Articles
Related Articles
More Stories
© 2026 Cedar & Bloom. All rights reserved.