Two recent healthcare incidents on Amazon infrastructure affected more than 13 million people between them, and neither involved a breach of Amazon.
What happened
Misconfigured permissions and inadequate access controls in business associate environments present a larger risk to patient data than the cloud services holding it, Healthcare IT News reported on September 3, 2026. Two recent incidents show the scale involved. CareCloud, which develops electronic health record, billing, and documentation technology, confirmed that an attacker reached one of its Amazon Web Services environments, with the HHS Office for Civil Rights breach portal recording more than 3.7 million individuals affected. Aesto Health, a data migration and archiving company, reported an incident from December 2025 affecting 9,540,683 people. Medtronic and McKesson were separately compromised through Salesforce environments, with ShinyHunters claiming responsibility for obtaining employee credentials by telephone in both cases.
Going deeper
Amazon secures the underlying cloud infrastructure while the healthcare technology company remains responsible for its applications, credentials, and access configuration. Aesto reported that an unauthorized party reached a portion of its own infrastructure hosted on AWS, which describes something different from a compromise of the platform itself. Pete Basica, founder and chairman of a digital therapeutics and remote patient monitoring platform, raised two questions the public information does not answer, namely why a single point of entry could reach records belonging to more than nine million people, and why monitoring systems did not identify and halt the activity before the data left the environment. Cloud breaches begin with failures involving people, permissions, software, or configuration, and stolen employee passwords, access keys, or security tokens open the pathway.
What was said
"The name of the cloud provider is not a security strategy," Basica said, speaking to Healthcare IT News. "Neither is a certification or an annual security review." On what the numbers represent, he pushed back on treating them as statistics, "Each record belongs to a real person who trusted a healthcare provider to protect some of the most private information that exists about them. A credit card can be cancelled and replaced; a person cannot easily replace a Social Security number, date of birth or medical history."
In the know
If stolen credentials carry the right to decrypt information, the system may hand readable patient records to an attacker because it treats the request as legitimate, Basica said. Encryption protects data from anyone without authorized access, which is what makes a valid credential the point where it stops helping. One compromised account with broad permissions can move between databases, reach multiple storage locations, and pull records belonging to numerous healthcare clients, using the platform's own administrative tools and the programming interfaces that let software request data automatically, with every request appearing authorized throughout. Basica listed four conditions for blocking data from leaving after an intrusion: security built into the architecture, limited access, separation between healthcare clients, and immediate identification of unusual activity.
The big picture
When millions of patient records sit in one vendor's environment, the failure of one company can affect patients across many unrelated healthcare organizations, Basica told Healthcare IT News, and patients frequently have never heard of the company holding their data. He noted that basic identity information from these breaches already sits in criminal databases after years of healthcare and consumer incidents, and that criminals benefit when previously stolen information is confirmed, updated, and combined with new material. An address, insurance identification number, financial account, driver's license number, and diagnosis together make an existing identity profile more complete. Every healthcare technology company holding patient information should design its systems expecting that someone will eventually get through the first door, with the measure being whether that person can reach the second and the third.
FAQs
What is the shared responsibility model?
Cloud providers secure the physical infrastructure, hypervisors, and platform services, while customers remain responsible for their own applications, data, identity management, and configuration. Most publicized cloud breaches trace to the customer side of that division rather than to the provider.
Does a HIPAA business associate agreement cover cloud configuration?
The agreement establishes obligations for protecting protected health information, and cloud providers offering services to covered entities are business associates. Configuration of the customer's own environment falls to the customer regardless of what the agreement says about the provider's duties.
What does separating healthcare clients involve technically?
Storing each client's data in distinct environments or partitions with separate access controls, so that credentials granting access to one client's records cannot reach another's. Without that separation, a single compromised account exposes every organization the vendor serves.
How should a provider assess a vendor's cloud environment?
Ask how client data is separated, what limits exist on bulk retrieval, what monitoring watches for unusual export volume, and how quickly unusual activity triggers a response. Certifications describe controls at a point in time and do not answer any of those questions.
