Aesto Health Breach Exposes Data of 9.54 Million Patients
The intrusion highlights vendor cloud risks that force providers to lead patient notification and regulatory responses.
Overview
- Aesto detected unauthorized activity on December 18, 2025 and after an extensive forensic and manual review confirmed on May 26, 2026 that attackers had accessed its AWS systems between December 2 and December 18, 2025.
- The company reported that 9,540,683 people were affected and that exposed fields include names, dates of birth, medical and insurance records, driver’s license and other ID numbers, financial and taxpayer IDs, and Social Security numbers for a limited group.
- Aesto says it engaged external cybersecurity experts, implemented additional security measures, opened a dedicated helpline, and began notifying its healthcare clients on June 26, 2026 while reporting the incident to HHS on July 31, 2026 with the breach posted to HHS’s portal on August 31, 2026.
- As a business associate, Aesto supports covered entities but does not replace their legal duty to notify patients, and at least two dozen provider clients across multiple states have been affected with some providers already sending their own patient notices.
- The breach underscores a 2026 pattern of high‑impact vendor and cloud configuration incidents and raises risks of downstream misuse of sensitive data, so regulators, providers and patients should watch for broader notification efforts, regulatory reviews and any signs of identity or financial fraud.