Skip to content
9.5 Million Impacted by Aesto Health Data Breach

9.5 Million Impacted by Aesto Health Data Breach

Feeds.Feedburner •Ionut Arghire • September 1, 2026

More than 9.5 million people had their personal and health information stolen in a data breach at healthcare technology company Aesto Health.

Based in Birmingham, Alabama, Aesto Health offers secure data migration, electronic health record (EHR) exchanges, and legacy data archiving services to healthcare providers and medical practices.

The data breach, the company said in a June 2026 incident notice , was discovered on December 18, 2025, and involved portions of its Amazon Web Services (AWS) infrastructure.

“Upon detecting the unauthorized activity, we immediately contained the incident and commenced a thorough investigation. As part of our investigation, we engaged leading cybersecurity experts to identify what personal information, if any, was involved,” Aesto Health said.

On May 26, 2026, the company’s investigation determined that hackers exfiltrated personally identifiable information (PII) and protected health information (PHI) between December 2 and 18.

The compromised information includes names, Social Security numbers, driver’s license numbers, other ID numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers.

Aesto Health has notified the US Department of Health and Human Services (HHS) that 9,540,683 individuals are impacted by the data breach. HHS added the company to its data breach portal on Monday.

At least two dozen Aesto Health healthcare provider clients across several states have been affected by the incident, some of which have chosen to notify the potentially affected people themselves.

Related: McKesson Confirms Data Breach as Attacker Deadline Looms

Related: Extortion Group Claims Manchester Airports Group Data Breach

Related: Personal Information Exposed in Apollo Global Data Breach

Related: CareCloud Data Breach Impact Grows to 3.7 Million Individuals

Ionut Arghire is an international correspondent for SecurityWeek.

More from Ionut Arghire

Extortion Group Claims Manchester Airports Group Data Breach

Berlin Won’t Pay Extortion Group Claiming Data Theft

Critical Isolated-vm Vulnerability Leads to RCE on Host

Rust Supply Chain Attack Linked to North Korean Hackers

Microsoft Patches Exploited Entra ID Vulnerability

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

WatchGuard Patches Critical Vulnerabilities

PaperCut Exploitation Escalates to Active Intrusions

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit

ServiceNow Patches 3 Critical Code Injection Vulnerabilities

McKesson Confirms Data Breach as Attacker Deadline Looms

What the Hugging Face Incident Teaches Security Leaders AI Agent Access

Anthropic Warns Claude Users of Infostealer Malware Infections

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs

Virtual Event: Attack Surface Management Summit 2026

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover?

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Flipboard Whatsapp Whatsapp Email

Extracted Entities