← All stories
● Covered by 3 sources · 15 reportsHigh impact15 negative

Multiple Healthcare Data Breaches Impact Over 30 Million Individuals

🔄 Updated 22d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • DentaQuest breach impacted over 23 million individuals.
  • Unlimited Technology Systems breach affected 3.8 million people.
  • MCBS breach exposed data for 1.26 million individuals.
  • CareCloud and Brown Health Medical Group-MA breaches affected over 350,000 and 311,000 respectively.
  • Compromised data includes names, SSNs, medical, and financial information.
  • MyDr, a Polish healthcare software provider, was breached.
  • The MyDr breach potentially affected 19 million people and 12,000 medical facilities.
  • The MyDr breach involved unauthorized access to historical data through April 2024.
  • Poland's e-Health Center replaced digital certificates for medical systems connecting to P1.
  • CareCloud breach affected 3.7 million individuals, not 350,000.
  • Threat actors accessed CareCloud's AWS environment between March 10 and March 16.
  • CareCloud breach also exposed payment card data for a limited subset of individuals.
  • CareCloud's AWS environment was accessed for eight hours.
  • CareCloud notified the SEC on March 24.
  • Over 270,000 affected individuals are in Texas.
  • Over 23,000 affected individuals are in South Carolina.
  • CareCloud distributed data breach notifications on July 25.
  • CareCloud's AWS environment was accessed between March 10 and March 16, 2026.
  • Aesto Health experienced a data breach affecting over 9.5 million individuals.
  • Aesto Health is a healthcare technology company based in Birmingham, Alabama.
  • Aesto Health's breach was discovered on December 18, 2025.
  • Hackers exfiltrated data from Aesto Health between December 2 and 18, 2025.
  • Aesto Health's incident notice was issued in June 2026.
  • Aesto Health's breach was confirmed internally on May 26, 2026.
  • Aesto Health's breach affected 29 healthcare providers.
  • Aesto Health's breach was reported to the U.S. Department of Health and Human Services.
  • Aesto Health's breach affected at least 30 healthcare organizations.
  • Aesto Health's breach exposed driver’s license numbers, financial account numbers, and health insurance data.
  • AdaptHealth experienced a data breach affecting over 4.1 million individuals.
  • AdaptHealth operates over 680 facilities across the US.
  • AdaptHealth's breach occurred in early June.
  • AdaptHealth's breach involved a threat actor gaining access to cloud-based applications.
  • The attacker stole a password file associated with insurance billing.
  • The hacker used social engineering to compromise a user session at a third-party contractor.
  • AdaptHealth announced the breach on August 14.
  • AdaptHealth reported 4,115,802 individuals affected to HHS.

Overview of Recent Healthcare Data Breaches

Multiple data breaches have been reported across the healthcare sector, collectively affecting over 30 million individuals. These incidents involved various healthcare-related companies, including benefits administrators, billing firms, and technology providers, with unauthorized access occurring between May 2025 and March 2026.

Major Incidents and Affected Numbers

DentaQuest, a dental and vision benefits administrator, reported a breach impacting over 23 million individuals. The incident, discovered on May 20, involved unauthorized access to its network between May 17 and May 20. Unlimited Technology Systems, a healthcare technology provider, disclosed a breach affecting 3.8 million people, with unauthorized access occurring between October 5 and October 10, 2025.

Medical Computer Business Services (MCBS), a medical billing company, experienced a breach in September 2025, exposing data for 1,261,464 individuals. The PEAR ransomware group claimed responsibility for this attack. Healthcare IT company CareCloud notified over 350,000 individuals about a breach in its AWS environment between March 10 and March 16, 2026. Brown Health Medical Group-MA (Lifespan Physician Group of Massachusetts) reported a breach from December 2025, affecting over 311,000 individuals.

Types of Data Compromised

The compromised information across these breaches includes a range of sensitive data. Common elements include names, addresses, Social Security numbers, dates of birth, health insurance information, medical information (such as diagnoses and treatment details), member identification numbers, and financial account information. In some cases, driver's license numbers, government ID numbers, and even personnel records were also exposed.

Impact and Response

These breaches highlight ongoing vulnerabilities within the healthcare industry's data security landscape. The affected organizations are notifying individuals and, in some cases, offering services such as credit monitoring, fraud consultation, and identity theft restoration. The incidents underscore the risks associated with healthcare data aggregators and technology providers.

Updates

🕒 2026-09-10 · new reporting from SecurityWeek
  • AdaptHealth experienced a data breach affecting over 4.1 million individuals.
  • AdaptHealth operates over 680 facilities across the US.
  • AdaptHealth's breach occurred in early June.
  • AdaptHealth's breach involved a threat actor gaining access to cloud-based applications.
  • The attacker stole a password file associated with insurance billing.
  • The hacker used social engineering to compromise a user session at a third-party contractor.
  • AdaptHealth announced the breach on August 14.
  • AdaptHealth reported 4,115,802 individuals affected to HHS.
🕒 2026-09-02 · new reporting from The Record
  • Aesto Health's breach affected at least 30 healthcare organizations.
  • Aesto Health's breach exposed driver’s license numbers, financial account numbers, and health insurance data.
🕒 2026-09-01 · new reporting from BleepingComputer
  • Aesto Health's breach was confirmed internally on May 26, 2026.
  • Aesto Health's breach affected 29 healthcare providers.
  • Aesto Health's breach was reported to the U.S. Department of Health and Human Services.
🕒 2026-09-01 · new reporting from SecurityWeek
  • Aesto Health experienced a data breach affecting over 9.5 million individuals.
  • Aesto Health is a healthcare technology company based in Birmingham, Alabama.
  • Aesto Health's breach was discovered on December 18, 2025.
  • Hackers exfiltrated data from Aesto Health between December 2 and 18, 2025.
  • Aesto Health's incident notice was issued in June 2026.
🕒 2026-08-19 · new reporting from BleepingComputer
  • CareCloud distributed data breach notifications on July 25.
  • CareCloud's AWS environment was accessed between March 10 and March 16, 2026.
🕒 2026-08-19 · new reporting from The Record
  • CareCloud's AWS environment was accessed for eight hours.
  • CareCloud notified the SEC on March 24.
  • Over 270,000 affected individuals are in Texas.
  • Over 23,000 affected individuals are in South Carolina.
🕒 2026-08-19 · new reporting from SecurityWeek
  • CareCloud breach affected 3.7 million individuals, not 350,000.
  • Threat actors accessed CareCloud's AWS environment between March 10 and March 16.
  • CareCloud breach also exposed payment card data for a limited subset of individuals.
🕒 2026-08-17 · new reporting from The Record
  • MyDr, a Polish healthcare software provider, was breached.
  • The MyDr breach potentially affected 19 million people and 12,000 medical facilities.
  • The MyDr breach involved unauthorized access to historical data through April 2024.
  • Poland's e-Health Center replaced digital certificates for medical systems connecting to P1.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

AdaptHealth, a healthcare company, experienced a data breach in June that exposed the personal, health, and insurance information of over 4.1 million individuals. A threat actor gained access to cloud-based applications through social engineering, leading to the theft of patient data. This incident highlights ongoing vulnerabilities in healthcare data security, affecting a significant number of patients.

Healthcare data company Aesto reported to federal regulators that a December cyberattack compromised the sensitive health data of more than 9.5 million people. The breach, which occurred on Aesto's Amazon Web Services infrastructure, affected at least 30 healthcare organizations and included names, Social Security numbers, and medical information. This incident is part of a trend of recent cyberattacks impacting healthcare data firms, highlighting ongoing vulnerabilities in the sector.

Aesto Health, a healthcare software provider, disclosed a data breach affecting more than 9.5 million individuals, with the intrusion occurring in December 2025 and confirmed in May 2026. The compromised data includes sensitive personal and medical information, impacting 29 healthcare providers. This incident highlights ongoing security challenges in the healthtech sector.

Healthcare technology company Aesto Health experienced a data breach affecting over 9.5 million individuals, with personal and health information exfiltrated from its AWS infrastructure. This incident highlights ongoing vulnerabilities in healthcare data security, impacting numerous patients and healthcare providers.

Healthcare IT company CareCloud disclosed that a data breach earlier this year impacted 3.7 million individuals. An unauthorized third party accessed one of CareCloud's AWS environments and exfiltrated data, leading to the distribution of data breach notifications to affected patients.

Electronic health record company CareCloud disclosed a data breach that impacted 3.7 million people after a hacker accessed one of its AWS environments for eight hours in March. The breach compromised personal, financial, and medical information, highlighting ongoing security vulnerabilities in the healthcare technology sector.

The CareCloud data breach, initially reported to affect hundreds of thousands, has been confirmed by the Department of Health and Human Services (HHS) to impact over 3.7 million individuals. Threat actors accessed CareCloud's AWS environment in March, exfiltrating sensitive personal and health information, including payment card data for a limited subset of individuals.

Polish authorities are investigating a cyberattack on MyDr, a healthcare software provider, which may have exposed data for nearly 19 million people and over 12,000 medical facilities. The incident prompted Poland's e-Health Center to replace digital certificates for medical systems connecting to the national health platform P1 as a precautionary measure.

Healthcare software provider Unlimited Technology Systems reported a data breach impacting over 3.8 million people, which occurred in October 2025. The breach exposed sensitive personal and health information, highlighting ongoing security challenges for healthcare data processors.

Unlimited Technology Systems, a healthcare technology provider, is notifying over 3.8 million individuals that their personal, medical, and health insurance information was stolen in a data breach that occurred in October 2025. This incident highlights ongoing cybersecurity risks within the healthcare technology sector, affecting a large number of patient records.

Brown Health Medical Group-MA, also known as Lifespan Physician Group of Massachusetts, is notifying over 311,000 individuals about a data breach that occurred in December 2025. The breach compromised personal, medical, and financial information, highlighting ongoing vulnerabilities in healthcare data security.

Healthcare IT company CareCloud is notifying at least 350,000 individuals about a data breach that compromised their personal, financial, and medical information. Hackers accessed an AWS environment within CareCloud Health between March 10 and March 16, 2026, exfiltrating data. This incident highlights ongoing vulnerabilities in healthcare data security, impacting a significant number of patients.

Medical Computer Business Services (MCBS) disclosed a network breach from September 2025 that exposed sensitive information for over 1.2 million people, including names, Social Security numbers, and medical history. This incident highlights the ongoing vulnerability of healthcare data aggregators to cyberattacks, impacting patient privacy and potentially leading to fraud.

Dental and vision benefits administrator DentaQuest is notifying millions of individuals about a data breach that exposed personal and dental health information. The breach, which occurred between May 17 and May 20, potentially affected over 23 million people and involved data such as Social Security numbers, health IDs, and treatment details. This incident highlights ongoing vulnerabilities in healthcare data security, impacting a significant portion of the US population reliant on dental benefits.

Medical Computer Business Services (MCBS) experienced a data breach in September 2025, affecting over 1.2 million individuals. The PEAR ransomware group claimed responsibility, accessing systems and potentially stealing sensitive personal and health information, which has since been made available for download.