Aesto Health Data Breach Exposes Sensitive Information of 9.5 Million Patients

Aesto Health says a December cloud infrastructure breach exposed protected health and personal information belonging to approximately 9.5 million people.
Aesto Health logo displayed on a red and dark blue digital cybersecurity background.

Aesto Health has confirmed that a data breach involving its cloud infrastructure exposed protected health and personal information belonging to approximately 9.5 million people, making the incident one of the largest healthcare breaches disclosed in 2026.

The Birmingham, Alabama-based healthcare data migration and archiving provider said an unauthorized actor accessed a portion of its Amazon Web Services infrastructure in December 2025. The compromised environment contained information belonging to patients of healthcare organizations that use Aesto’s services.

According to Aesto’s official security incident notice, the company determined on May 26, 2026 that protected health information may have been accessed and/or acquired during the intrusion.

More than 9.5 million people affected

The breach has been reported as affecting 9,540,683 individuals. Aesto’s own incident page does not provide the aggregate number, but the company has continued identifying healthcare organizations whose patient information was involved.

Aesto detected the security incident around Dec. 18, 2025 and launched an investigation with external cybersecurity specialists. The subsequent forensic investigation determined that unauthorized access occurred between approximately Dec. 2 and Dec. 18.

The company began notifying affected healthcare clients on June 26 after completing a forensic investigation and manual review of the potentially compromised information.

Individual notifications have continued into August as Aesto and affected healthcare providers determine which patients were involved.

Medical, identity and financial information exposed

The information involved varies between individuals and healthcare organizations. Aesto says potentially affected information includes:

  • Full names
  • Dates of birth
  • Medical information
  • Health insurance information
  • Driver’s license numbers
  • Financial account numbers
  • Individual taxpayer identification numbers
  • Other government identification numbers
  • Social Security numbers for a limited number of individuals

Individual breach notifications show that the specific medical information exposed can also vary considerably. In one notification filed with the Massachusetts Attorney General on behalf of Edwards County Medical Center, potentially compromised information included medical record numbers, hospital units and physician names.

Aesto said it has found no evidence that information involved in the incident has been used for identity theft or financial fraud.

Dozens of healthcare organizations involved

The incident has become a significant third-party healthcare breach because Aesto stores information on behalf of healthcare organizations rather than only its own employees or customers.

Aesto maintains an official list of covered entities affected by the incident. Updated Sept. 3, the page identifies dozens of healthcare organizations, including hospitals, community health centers, physician groups and specialist medical practices.

The affected organizations span multiple states, meaning the 9.5 million-person total represents patients whose information was held by Aesto on behalf of numerous healthcare providers.

The incident highlights the concentration of sensitive information that can exist within healthcare technology and data-management providers. A compromise at a single vendor can expose information originating from many otherwise unrelated medical organizations.

Lawsuits follow breach notifications

Aesto is also facing legal action following the disclosure. Multiple proposed lawsuits have been filed in the U.S. District Court for the Northern District of Alabama since late August, with some cases also naming affected healthcare organizations.

One complaint filed Sept. 1 names Aesto and Everside Health as defendants, while another filed the same day names Aesto and Village Practice Management Company, which operates as VillageMD. Additional complaints have been filed involving other healthcare organizations whose information was stored by Aesto.

The allegations in those lawsuits have not been adjudicated.

Patients face phishing and identity theft risks

The combination of identity information and healthcare data creates longer-term risks for affected patients. Names, dates of birth and contact information can support targeted phishing and impersonation attempts, while government identifiers and financial information may increase the potential for identity fraud where those fields were exposed.

The incident is particularly sensitive for individuals whose Social Security numbers, driver’s license numbers or financial account information were among the compromised fields.

Aesto said it has taken additional measures following the incident and continues to evaluate its security practices. Affected individuals should refer to their individual notification because the categories of information exposed differ between patients and healthcare providers.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site