
Healthcare data migration and archiving provider Aesto has disclosed to the US Department of Health and Human Services (HHS) that a data breach announced earlier this year affected 9,540,683 individuals.
The incident involved unauthorized access to part of Aesto’s Amazon Web Services (AWS) infrastructure in December 2025 and potentially exposed sensitive patient information, including medical, insurance, financial, and government identification data.
Aesto detected the intrusion on or about December 18, 2025, contained the activity, and launched an investigation with external cybersecurity experts. The investigation determined that an unauthorized actor may have accessed or acquired data between approximately December 2 and December 18, 2025.
Aesto, LLC, doing business as Aesto Health, is a Birmingham, Alabama-based company that provides healthcare organizations with data migration and archiving services. Because it stores information on behalf of multiple healthcare entities, a breach of its systems can affect patients belonging to numerous providers.
Following a forensic investigation and manual document review, Aesto confirmed on May 26, 2026, that files involved in the incident contained protected health information belonging to patients of various covered entities.
The exposed information varied by individual and may include:
- Names
- Dates of birth
- Medical information
- Health insurance information
- Driver’s license numbers
- Financial account numbers
- Individual taxpayer identification numbers
- Other government-issued identification numbers
- Social Security numbers
Aesto said Social Security numbers were potentially involved for only a limited number of people and that it has found no evidence of identity theft or financial fraud related to the incident.
The company began notifying affected healthcare clients on June 26.
A separate notification letter dated August 21 offered affected individuals 24 months of complimentary Experian IdentityWorks services, including credit monitoring, identity restoration support, and identity theft insurance.
Aesto has not publicly identified the threat actor behind the attack or explained how its AWS environment was compromised. Its notices also do not indicate whether ransomware was deployed or whether the attackers attempted to extort the company.
Affected individuals should monitor bank and credit accounts, review their credit reports for suspicious activity, and check health insurance explanation-of-benefits statements for unfamiliar claims. Those whose Social Security numbers or other sensitive identifiers were exposed should also consider placing a credit freeze with Equifax, Experian, and TransUnion.







Leave a Reply