2 Remove Virus

Aesto Health data breach exposes information of 9.5 million patients

Aesto Health has disclosed that more than 9.5 million people were affected by a data breach involving protected health information stored within the company’s systems.

 

 

Aesto Health is a private healthcare technology company that provides software-as-a-service solutions to medical organizations. Its technology is used to migrate, archive, and access patient information, including during electronic health record system replacements and medical practice acquisitions. This means the company can hold sensitive information belonging to patients of numerous healthcare providers.

According to a filing with the US Department of Health and Human Services, the incident affected 9,540,683 individuals, making it one of the larger healthcare data breaches disclosed in 2026.

The intrusion itself occurred months before the full scale of the incident became public. An unauthorized actor had access to affected systems between approximately December 2nd and December 18th, 2025.

Aesto later brought in external specialists to conduct a forensic investigation and review potentially compromised documents. On May 26th, 2026, the company determined that protected health information belonging to patients of several healthcare clients may have been accessed or acquired during the intrusion.

The company publicly disclosed the cyberattack on June 24th, initially describing the affected environment as a limited part of its Amazon Web Services infrastructure.

The information exposed differs between individuals, but the compromised records may contain highly sensitive personal, medical and financial details. Affected information includes names, dates of birth, medical information, health insurance details and Social Security numbers.

Some records also contained driver’s license numbers, financial account numbers, individual taxpayer identification numbers and other government-issued identification numbers.

Because Aesto provides technology to healthcare organizations rather than primarily treating patients itself, the breach has consequences extending to organizations using its services. The incident has reportedly affected patients associated with 29 healthcare providers.

Aesto began sending notifications to affected individuals on August 21st. Those receiving notices are being offered 24 months of identity theft protection and credit monitoring through Experian.

The combination of identity information, government identifiers, financial details, and medical records makes the exposed data particularly sensitive. Unlike passwords, information such as Social Security numbers and medical histories cannot simply be replaced following a breach.

Aesto has not publicly identified who was responsible for the intrusion. As of the latest disclosure, no ransomware operation or other known threat group had publicly claimed responsibility for the attack.