HomeData BreachesAesto Health Breach Exposes Data of 9.5 Million Patients Across 29 Healthcare...

Aesto Health Breach Exposes Data of 9.5 Million Patients Across 29 Healthcare Providers

A healthcare data services company called Aesto Health has confirmed that a cybersecurity incident exposed sensitive information belonging to more than 9.5 million patients, making it one of the largest healthcare data breaches disclosed so far this year. The company, legally known as Aesto LLC, provides software that helps healthcare organizations migrate, archive, and access patient records when they switch between electronic health record systems, which meant the breach reached well beyond Aesto’s own direct customers.

According to breach notifications and the company’s own statement, the intrusion took place between December 2 and December 18, 2025. Aesto said it did not confirm that data had actually been accessed or taken until May 26, 2026, following a forensic investigation, and it did not begin notifying the public until posting a notice on its website on June 24, 2026. Individual letters to affected patients went out even later, starting August 21, 2026, a gap of roughly eight months between the intrusion and direct notification to the people affected.

In total, 9,540,683 individuals had information exposed. Because Aesto works as a data processor behind the scenes for other healthcare organizations, the exposure touched patients of 29 separate healthcare providers, including VillageMD, Everside Health, Marana Health, and Together Women’s Health. The data involved was extensive: full names, dates of birth, medical information, health insurance details, driver’s license numbers, financial account numbers, individual taxpayer identification numbers, and Social Security numbers all appear on the list of compromised data types.

Aesto has said the incident involved unauthorized access to “a limited portion” of its Amazon Web Services cloud infrastructure, but it has not disclosed the specific method attackers used to get in, such as whether stolen credentials, a software vulnerability, or a misconfiguration was responsible. No ransomware or extortion group has publicly claimed responsibility for the breach, and no stolen data has surfaced on a leak site as of this writing, which sets it apart from several other recent healthcare breaches where attackers have posted samples of stolen records to pressure victims into paying.

The company reported the incident to the U.S. Department of Health and Human Services, as required under federal health privacy rules for breaches affecting protected health information. Aesto is offering affected individuals 24 months of identity theft protection and credit monitoring through Experian at no cost.

Because the data exposed includes Social Security numbers, government identification numbers, and financial account details alongside medical records, security researchers generally consider this combination especially valuable to criminals for identity theft and fraud, not just for the kind of targeted phishing that medical data alone can enable. Patients who received a notification letter from Aesto Health or from one of the healthcare providers it works with are advised to enroll in the offered monitoring service and to watch their financial accounts and insurance statements for unfamiliar activity.

Source: This story is based on reporting from BleepingComputer.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular