Skip to main content
Emerging ThreatsData Breaches

Aesto Health Data Breach Exposes 9.5 Million Patients

Hospital corridor with staff, patient rooms, and medical device near window.

"a limited portion" of its Amazon Web Services infrastructure had been compromised, Aesto Health told the public on June 24 — a brief phrase that belies a breach affecting millions and months of internal investigation.

Timeline: intrusion December 2–18, 2025; internal confirmation May 26, 2026; public notice June 24, 2026

Aesto LLC, doing business as Aesto Health, says a malicious actor accessed its network between on or about December 2, 2025, and December 18, 2025. The company reported that an extensive forensic investigation and manual document review led to an internal confirmation of the incident on May 26, 2026. Aesto first informed the public on June 24 via a notice on its website.

Scope: 9,540,683 individuals and the type of data accessed

In a report to the U.S. Department of Health and Human Services, Aesto Health stated that the breach affects 9,540,683 individuals. According to the company, the information accessed or acquired included full names, dates of birth, medical information, driver’s license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers.

Who Aesto Health serves and which providers are indirectly affected

Aesto Health provides software-as-a-service tools that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices. HIPAA Journal reports the incident indirectly impacts 29 healthcare providers, naming VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women’s Health among those affected.

Notification and remediation: August 21 notices and Experian monitoring offer

The company began notifying impacted individuals on August 21, providing details about the incident and instructions to enroll in a 24-month identity theft protection and credit monitoring service through Experian. The public notice and the HHS filing are the principal disclosures Aesto has made public to date.

What this means for technologists, affected patients, and 29 healthcare providers

  • Technologists and security teams: The incident underscores the challenges of protecting data held by third-party SaaS providers that support EHR migration and archival operations. The Blue Report 2026 — cited in the source material — notes that "overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply," a measurement drawn from 338 million simulations across customer environments.
  • Affected patients: More than 9.5 million people were told their personal and medical information may have been accessed. Aesto’s offer of 24 months of identity theft protection and credit monitoring through Experian is the remediation step the company is publicizing.
  • The 29 healthcare providers named indirectly: Organizations that relied on Aesto’s services will need to reconcile their inventories of exposed records, coordinate notifications, and evaluate contractual and compliance obligations following Aesto’s disclosures.

The Aesto Health breach arrives amid a sequence of incidents at other health-technology vendors: the source lists iRhythm, Xolis, Medronic, MCBS, Health-ISAC, Unlimited Technology Systems, CareCloud, Nutex Health, and McKesson as recent examples. At the time of Aesto’s disclosure, no threat groups had publicly claimed responsibility for the attack.

Aesto’s account — anchored in a forensic investigation completed by external specialists and laid out in its statement to HHS — sets out concrete dates, the scale of individuals affected, and the classes of sensitive data involved. The company's role as a data custodian for healthcare migrations and acquisitions places its incident in a broader pattern the source documents: multiple healthtech software providers have suffered compromises in recent months. The Blue Report 2026 excerpt in the source material highlights a tactical reality worth noting here: defenders’ measured prevention performance can fall away quickly once adversaries obtain valid credentials.

Final note: Aesto has disclosed the incident to regulators and began individual notifications on August 21; it has offered two years of identity protection via Experian. The public record, as presented by the company and summarized to HHS, leaves open who carried out the intrusion and how the initial access occurred — facts the company’s forensic statement did not attribute to any named threat actor.

Original story