News

Aesto Health breach hits 9.5 million patient records

Aesto Health told HHS that 9,540,683 people are in a breach that ran 2 to 18 December 2025 on a slice of AWS. Stolen fields include SSNs, driver's licenses, medical and insurance data. HIPAA Journal counted 29 provider clients. No public threat-group claim as of 1 September.

Aesto Health breach hits 9.5 million patient records

Aesto Health, a Birmingham, Alabama vendor that migrates EHR data, runs exchanges, and archives legacy records for providers, told HHS that 9,540,683 people are in the impact set. SecurityWeek (Ionut Arghire, 1 September 2026) reported the company was added to the HHS breach portal on the Monday before that write-up.

This is a company incident notice plus an HHS portal filing, as covered by the trade press. It is not a CISA advisory. Aesto has not confirmed ransomware, and as of the 1 September coverage no named threat group had publicly claimed the attack.

Aesto's June notice said it discovered unauthorized activity on 18 December 2025 in a limited portion of its AWS infrastructure, contained it, and hired outside experts. On 26 May 2026 the investigation concluded that attackers took PII and PHI between 2 and 18 December 2025. The public website notice went up 24 June. Individual notices started 21 August, with 24 months of Experian identity theft protection and credit monitoring.

The stolen fields, per the company and the HHS filing, include names, Social Security numbers, driver's license numbers, other ID numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer ID numbers. That is a full identity-plus-clinical bundle, not a shallow contact list.

HIPAA Journal counted 29 healthcare provider clients in the cascade, among them VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women's Health, BleepingComputer (Bill Toulas) reported. SecurityWeek said at least two dozen clients across several states were affected, with some providers sending their own notices. The two counts sit next to each other. Treat 29 as HIPAA Journal's tally, not as proof that every named client's full EHR was dumped.

The path is a healthtech data-migration vendor, not the hospital's own EHR, the same third-party pattern as the Manchester Airports Group customer-data incident and the Thomson Reuters C-Track court-records notice. Cloud-vendor access also sits behind the Azure data advertised against Fortune 500 names. This file is an AWS exfiltration, not a hypervisor host-escape like the VMware Workstation and Fusion patches.

If you run health-system security, privacy, or vendor risk, pull Aesto and peer EHR-migration vendors into your breach-notice workflow this week. Confirm whether your organization is one of the roughly 29 clients, and enroll staff or patients who match the December 2025 window in the Experian offer if the 21 August notice makes them eligible.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free