Particle.news
Download on the App Store

Aesto Health Breach Exposes 9.54 Million Patient Records

A December 2025 intrusion into part of the company’s AWS environment highlights vendor risk to health systems, raising the chance of identity and medical fraud for affected patients.

Overview

  • Aesto detected unauthorized activity on December 18, 2025, and on May 26, 2026 confirmed that attackers accessed its AWS environment between December 2 and December 18, 2025, with the company reporting 9,540,683 people affected to HHS.
  • Exposed information varied by person and included full names, dates of birth, medical and insurance records, driver’s license and other government ID numbers, financial account and taxpayer ID numbers, and Social Security numbers for a limited set of records.
  • The incident affects two dozen to roughly 29 healthcare provider clients, some of which have begun contacting patients directly as covered entities responsible for notification under HIPAA.
  • Aesto engaged external cyberforensics teams, reported the breach to the HHS Office for Civil Rights, began individual notifications on August 21, 2026, and is offering 24 months of Experian credit monitoring while saying it has found no evidence so far of identity theft, financial fraud, or public posting of the data.
  • The breach follows a pattern of 2026 attacks that target third‑party healthtech vendors and cloud infrastructure, underscoring how vendor compromises can cascade into operational, legal, and privacy risks for patients and health systems.