Clingantry

From ClingantryAI Health Regulator News

healthcare ai & robotics — regulatory & breach intelligence, sourced only from primary government record


Tagged “alabama” · 2 entries

Aesto, LLC reports massive data breach affecting nearly 10 million records

Aesto, LLC, a Business Associate based in Alabama, filed a breach report with HHS OCR on July 31, 2026. The filing covers a hacking/IT incident that compromised the protected health information of 9,540,683 individuals. The breach occurred on a network server. Because Aesto is a Business Associate, your organization may be affected if you use their services for administrative or technical support. Review your contracts and vendor risk assessments to determine if you are a client of Aesto. If you are, contact your vendor management team immediately to understand the specific data exposed and any required notification steps for your own patients or members.

Alabama: starting October 1, AI can't be the one denying coverage — a clinician must decide

Alabama's new law (signed April 17, 2026, effective October 1, 2026) says a health insurer can't rely only on AI to decide whether care gets covered — any decision to deny or reduce coverage has to be made by a qualified healthcare professional. Insurers must also tell enrollees that AI is used in coverage decisions, base prior-auth determinations on the individual patient's medical history rather than group data alone, and certify annually to the state that their AI is monitored for accuracy and doesn't discriminate. If you're in Alabama, this is leverage: after October 1, an AI-only denial is something you can push back on by law.

← Back to AI Health Regulator News