grid
Abstract circular gradient with concentric rings in blue, green, yellow, and red fading into black background.
5 min read

Aesto Health Data Breach Exposes Records of 9.5 Million Patients

Aesto Health data breach
Published on
September 2, 2026

Aesto Health has told federal regulators that an intrusion into its cloud infrastructure exposed the protected health information of 9,540,683 people. The Alabama company treats no patients and runs no clinic. It migrates and stores medical records for hospitals and medical practices, a role that gathered archives from dozens of provider organizations into one environment. The Aesto Health data breach reached that environment over sixteen days in December 2025.

Attackers held access to part of the company's Amazon Web Services infrastructure between December 2 and December 18, 2025. Aesto detected the unauthorized activity around December 18 and contained it, then brought in outside forensic specialists. Establishing what the intruders actually reached took another five months.

What the Aesto Health Data Breach Exposed

The company closed its forensic investigation and manual document review on May 26, 2026. It confirmed that protected health information belonging to patients of multiple client organizations may have been accessed or copied. The exposed records include:

  • Full names and dates of birth
  • Medical information, treatment histories, and claims or billing records
  • Health insurance details
  • Driver's license numbers and state identification numbers
  • Financial account numbers
  • Individual taxpayer identification numbers and other government identifiers
  • Social Security numbers

Aesto says the elements vary by individual, and that Social Security numbers were involved for a smaller subset. That distinction offers limited comfort. A name, a date of birth, an insurance policy number, and a diagnosis together support medical identity fraud, with no Social Security number required.

The Archive Problem Behind the Numbers

Twenty-six named client organizations produced more than nine million patient records. The arithmetic looks impossible until you consider what the company actually does. Practices hire Aesto when they replace an electronic health record system or acquire another clinic. The old records still have to live somewhere, and retention rules keep them intact for years after a migration finishes.

So the archive grows while the clinical relationship ends. Someone who visited a rural hospital once in 2014 and never returned still has a file sitting in it. Most of the affected clients are small: county hospitals, community health centers, and women's health groups across Alabama, Kansas, Montana, Arizona, and New York. Decades of accumulated patient history ended up in a single place.

That concentration is the entire point of the service. It also explains how one intrusion at one vendor reached this many people.

Certification Did Not Prevent the Intrusion

Aesto holds HITRUST certification and a SOC 2 Type 2 attestation, published through a trust center built for compliance teams and procurement reviewers. Those are the exact credentials healthcare buyers ask for before signing a business associate agreement. Both were in place when the attackers got in.

Neither framework is worthless, but both describe controls at a moment in time rather than guaranteeing an environment holds under attack. Aesto has not disclosed how the intruders reached its AWS infrastructure. No statement so far addresses stolen credentials, misconfiguration, an exposed access key, or any other entry path. Client organizations reviewing their own exposure have nothing specific to test against.

Eight Months From Detection to Patient Notification

The company posted a public notice on June 24, 2026, then began informing its covered entity clients two days later. Individual patients started receiving letters on August 21, roughly eight months after the intrusion ended.

The HIPAA Breach Notification Rule requires notice within 60 days of discovery. Aesto's account treats May 26, 2026, as the point of confirmation rather than December 18, 2025, when it detected the activity. Regulators at the HHS Office for Civil Rights will decide which date starts the clock. The answer carries real consequences.

Responsibility complicates the picture further. Under HIPAA, the covered entity rather than the business associate bears ultimate responsibility for notifying patients. Some clients delegated that job back to Aesto, and others filed on their own. Disclosures tied to this incident have appeared across state attorney general offices since July.

The Client Count Is Still Moving

Aesto's published list named 26 covered entities as of August 21. Independent tracking puts the total at 30 or more. The additions include Everside Health, Village Practice Management, Lone Star Community Health Center, Murfreesboro Medical Clinic, Quincy Valley Medical Center, and Stanislaus County Health Services Agency.

State filings show partial totals: 80,622 South Carolina residents, 37,253 in Washington, 731 in Oregon, and 91 in Vermont. Village Practice Management has confirmed more than 25,000 affected patients of its own, and Everside Health reported roughly 22,000 in Washington alone. No threat group has claimed responsibility, and none of the stolen material has surfaced publicly. Several plaintiff firms have opened class action investigations.

What Affected Patients Should Do

Anyone treated by one of the named providers should assume their records are included. That holds even if the visit happened years ago and the practice has since closed or changed hands. Aesto is offering 24 months of identity theft protection and credit monitoring through Experian, with enrollment instructions in the notification letters.

Explanation of benefits statements deserve a closer read than usual over the coming year. Claims for services you never received are the clearest early signal that medical identity fraud has started. That kind of fraud can corrupt a medical record in ways a credit report never shows. A fraud alert or a credit freeze costs nothing and blocks the most common use of a stolen Social Security number.

The scale of this incident will likely keep shifting as more client organizations complete their reviews and file their own notifications. What is already clear is that patients had no relationship with the company holding their records. They had no say in the arrangement and no way to know their history was there at all.

Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.