Aesto Health breach exposed data of 9.5 million patients

Aesto Health told HHS that 9.5 million people had personal and health data stolen from its AWS infrastructure.

CSBadmin
2 Min Read

Healthcare technology vendor Aesto Health is disclosing a breach in which personal and health records for over 9.5 million individuals were taken. Aesto, a Birmingham, Alabama company, builds and runs services that migrate, exchange and archive electronic health records for providers, exactly the kind of infrastructure that concentrates patient data in one place.

The breach involved portions of the company’s Amazon Web Services infrastructure. Aesto said in a June 2026 incident notice that it discovered unauthorized activity on December 18, 2025, and its investigation later determined hackers exfiltrated data between December 2 and 18. The stolen fields span names, birth dates, Social Security numbers, driver’s license numbers, financial account numbers, medical and health insurance details, and taxpayer identification numbers.

The company told HHS that 9,540,683 individuals are affected, and the agency listed it on the public breach portal Monday. More than two dozen Aesto provider clients in several states were touched, and some opted to handle their own victim notifications.

The company said it contained the incident immediately and engaged cybersecurity experts to support the investigation. The case is another reminder that third-party healthcare vendors concentrate risk: a single vendor’s cloud compromise can pull in records from dozens of medical practices at once.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.