Aesto Health AWS environment breach (9.5 million patients)
Healthcare data migration and archiving vendor Aesto Health reported that an intruder accessed part of its Amazon Web Services environment in December 2025, exposing the medical and identity data of 9,540,683 patients across dozens of provider clients.
- Victim
- Aesto Health
- records
- 9.5M
- users
- 9.5M
On 1 September 2026, the scale of a breach at Aesto Health became public when the incident appeared on the U.S. Department of Health and Human Services breach portal with 9,540,683 affected individuals, making it one of the largest healthcare data breaches disclosed in 2026. Aesto, based in Birmingham, Alabama, provides data migration, legacy data archiving and electronic health record (EHR) exchange services to medical practices and health systems.
The company said an unauthorized third party accessed a portion of its Amazon Web Services (AWS) environment between 2 and 18 December 2025, when the activity was identified. Because Aesto holds archived and migrated records on behalf of its customers, the patients affected belonged to at least 39 healthcare provider clients rather than to Aesto itself.
What was exposed
The data varied by individual but included full names, Social Security numbers, partial dates of birth, driver's license and state ID numbers, taxpayer identification numbers, financial account numbers, health records, medical histories, claims and billing information, and health insurance details. State filings recorded tens of thousands of residents in South Carolina and Washington among those affected. No threat actor publicly claimed the attack, and Aesto said it had no evidence of identity theft or fraud linked to the incident.
Why it matters
Archiving and migration vendors concentrate data from many providers, often including records of former patients that the originating practices no longer actively manage. The six-month gap between detection and the start of client notification, followed by a further delay before individual letters, illustrates how long patients can remain unaware that a vendor several steps removed from their care has lost their data.
Timeline
An unauthorized third party begins accessing part of Aesto Health's AWS environment.
Aesto Health detects the unauthorized activity and contains it.
Aesto Health begins notifying its covered-entity healthcare clients.
The breach is reported to the HHS Office for Civil Rights.
The HHS breach portal entry showing 9,540,683 affected individuals is widely reported.
Sources
- hipaajournal.comhttps://www.hipaajournal.com/aesto-health-data-breach/
- securityweek.comhttps://www.securityweek.com/9-5-million-impacted-by-aesto-health-data-breach/
- beckershospitalreview.comhttps://www.beckershospitalreview.com/healthcare-information-technology/cybersecurity/aesto-health-data-breach-hits-9-5-million-patients-what-to-know/