VYPR
breachPublished Sep 1, 2026· 1 source

Aesto Health Data Breach Exposes Personal and Health Information of 9.5 Million Individuals

Healthcare technology company Aesto Health has disclosed a significant data breach impacting approximately 9.5 million individuals, compromising sensitive personal and protected health information.

Aesto Health, a healthcare technology firm based in Birmingham, Alabama, has reported a substantial data breach that has exposed the personal and protected health information of over 9.5 million individuals. The company, which specializes in secure data migration, electronic health record (EHR) exchanges, and legacy data archiving for healthcare providers, discovered the unauthorized activity on December 18, 2025.

Following the detection of suspicious activity within portions of its Amazon Web Services (AWS) infrastructure, Aesto Health promptly initiated an investigation. The company engaged leading cybersecurity experts to ascertain the full scope of the incident and identify any compromised personal information. The investigation concluded on May 26, 2026, confirming that malicious actors had exfiltrated sensitive data between December 2 and December 18, 2025.

The compromised data includes a wide range of personally identifiable information (PII) and protected health information (PHI). Affected individuals may have had their names, Social Security numbers, driver's license numbers, other identification numbers, dates of birth, financial account details, medical information, health insurance details, and taxpayer identification numbers accessed by unauthorized parties.

Aesto Health has formally notified the U.S. Department of Health and Human Services (HHS) of the breach, reporting that 9,540,683 individuals were impacted. The company was subsequently added to the HHS data breach portal. The incident has affected at least two dozen Aesto Health clients, including healthcare providers across multiple states, some of whom have opted to notify their affected patients directly.

The full extent of the breach and the specific methods employed by the attackers are still under investigation. However, the scale of the incident underscores the persistent threats facing the healthcare sector, which holds vast amounts of sensitive personal and medical data.

This breach serves as a stark reminder of the critical importance of robust cybersecurity measures within healthcare technology providers. The exfiltration of such comprehensive data sets can lead to significant risks for individuals, including identity theft, financial fraud, and potential misuse of medical information.

Organizations like Aesto Health are entrusted with highly sensitive data, making their security posture paramount. The incident highlights the ongoing challenges in protecting cloud-based infrastructure from sophisticated cyber threats and the need for continuous vigilance and investment in cybersecurity defenses.

As investigations continue, affected individuals are advised to remain vigilant for any signs of identity theft or fraud and to follow guidance provided by Aesto Health and their healthcare providers regarding protective measures.

Synthesized by Vypr AI