"Three separate healthcare cybersecurity incidents in three weeks represent an alarming escalation that directly threatens patient care alongside data privacy," said Damon Small, a member of the board of Xcape, Inc.
Aesto Health: a December intrusion confirmed only in May, 9.5 million affected
Aesto Health has confirmed a breach impacting more than 9.5 million individuals and 30 healthcare providers. Compromised records include Social Security numbers, medical histories, financial account information, insurance data and claims, and billing data. The company’s incident — which, according to reporting here, occurred in December 2025 — took five months to confirm and was posted to the HHS breach portal this week, making it “2026’s second-largest confirmed healthcare breach to date,” the reporting states.
Nutex Health and The Gentlemen: exfiltration and public threats
Nutex Health disclosed that hackers exfiltrated several types of information: patient, employee, healthcare provider, business, and financial data. The Gentlemen ransomware group is publicly threatening to publish stolen data from Nutex Health’s 27 hospitals, according to the source material. Nutex disclosed the breach to the SEC on August 24, and a class action was filed in Texas three days later — before the company had finished determining precisely what was stolen.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildLuminis Health: active attack disabling systems, patient access affected
Luminis Health is reported to be in the midst of an active cyberattack that has disabled certain systems in its healthcare network. That disruption has affected patients’ abilities to access certain services; patients are reportedly calling a phone number instead of logging into MyChart, reflecting a fallback to manual or telephonic processes while systems are down.
How Damon Small, John Strand, and Denis Calderone frame the risks
- Damon Small (Board of Directors, Xcape, Inc.) emphasized operational risk: “When cyber incidents cut off access to electronic health record (EHR) systems, clinical operations grind to a halt, delaying necessary care and risking patient safety.” He urged that healthcare executives must elevate IT security to a core operational priority, enforce strict third‑party vendor risk controls, restrict network exposure, and maintain offline, immutable backups.
- John Strand (owner, Black Hills Information Security, Inc.) warned about normalization: “We’re becoming numb to breaches of this magnitude,” noting that incidents of this scale once drew front‑page coverage but now often fail to register for the broader public.
- Denis Calderone (CTO, Suzu Labs) placed these incidents in a broader pattern: he described 2026 as “a bad year” for healthcare, cataloguing other large exposures (McKesson at 284 million claimed records two days earlier; DentaQuest at 15 million). He noted that the legal and regulatory response is accelerating — citing the Nutex SEC disclosure, rapid class‑action filings, and, in April, HHS’s Office for Civil Rights settling four ransomware investigations for a combined $1.165 million where the common root cause was “failure to conduct an adequate risk analysis.”
What this means for technologists, regulators, and patients
- Technologists and security teams: the incidents underscore the operational consequences of EHR downtime and the need for immutable offline backups, stronger vendor risk management, and reduced network exposure — all measures explicitly recommended by Damon Small in the reporting.
- Policymakers and regulators: Denis Calderone notes the legal machinery has accelerated — SEC disclosures and near‑immediate class actions are now routine, while HHS settlements and publicly available government guidance are being cited by plaintiffs to define a baseline standard of care.
- Patients and healthcare providers: the simultaneous occurrence of data exfiltration and active operational outages means both long‑term privacy harms (exposed Social Security numbers, financial and medical data) and immediate care disruptions (systems down, MyChart inaccessible, reliance on phones and manual processes).
The three breaches — Aesto Health, Nutex Health, and Luminis Health — together illustrate overlapping threats: large‑scale data exfiltration, ransomware groups publicly threatening publication, and active attacks that interrupt clinical operations. Security leaders in the reporting argue these are not isolated IT problems but operational crises that affect patient safety and invite legal and regulatory consequences.
As Denis Calderone summarized the fast‑moving environment: “The window between breach disclosure and lawsuit has effectively collapsed,” and plaintiffs are citing existing HIPAA Security Rule requirements and CISA recommendations to establish a legal baseline. As Damon Small put it, “Treating hospital IT like an ancillary expense works right up until the emergency room is forced back to pen and paper.”
Will health system leadership treat these events as a signal to reorganize funding, governance and third‑party controls around clinical IT? The reporting leaves that question squarely to executives now balancing operational, legal and patient‑safety imperatives.




