9.5 Million Impacted by Aesto Health Data Breach

Summary: Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.

Aesto Health Data Breach Exposes Personal and Medical Information of 9.5 Million People

A major healthcare data breach at Aesto Health has affected more than 9.5 million individuals, exposing a combination of personal, financial and medical information stored within the company’s cloud infrastructure.

The Birmingham, Alabama-based healthcare technology provider disclosed that attackers gained unauthorized access to portions of its Amazon Web Services environment in December 2025. Aesto Health provides services including electronic health record exchanges, legacy medical-data archiving and secure data migration, placing the company in a particularly sensitive position within the healthcare supply chain.

Attackers spent more than two weeks accessing data

Aesto Health detected unauthorized activity on December 18, 2025 and began an investigation with external cybersecurity specialists. The investigation eventually determined that attackers had been exfiltrating information between December 2 and December 18, providing an approximately two-week window in which data was potentially accessible.

On May 26, 2026, the company concluded that the stolen files contained both personally identifiable information (PII) and protected health information (PHI). The compromised data varies by individual but may include names, Social Security numbers, driver’s license and other identification numbers, dates of birth, financial account numbers, taxpayer identification numbers, medical information and health insurance information.

The combination makes the incident particularly serious. Unlike a compromised password, information such as Social Security numbers, historical medical records and dates of birth cannot simply be reset after a breach.

More than 9.5 million people are affected

Aesto Health has now reported the incident to the US Department of Health and Human Services, identifying 9,540,683 affected individuals. HHS added the breach to its public data-breach portal on August 31.

The enormous number of victims reflects Aesto Health’s position as a technology provider rather than a single hospital or medical practice. At least two dozen healthcare organizations across multiple US states have been affected, with some clients choosing to notify impacted patients directly.

This type of incident demonstrates the concentration risk created by healthcare technology vendors. An attacker who compromises a hospital may obtain information from one healthcare organization. Compromising a company responsible for migrating, exchanging or archiving records can potentially provide access to information originating from many providers simultaneously.

Cloud infrastructure is only as secure as its configuration and identities

The fact that the compromised information was stored within AWS infrastructure does not by itself indicate a vulnerability in Amazon’s cloud platform. Aesto Health has not publicly disclosed the precise initial-access vector, and there is currently no evidence in the SecurityWeek report suggesting that AWS itself was breached.

That distinction is important as healthcare organizations increasingly move sensitive workloads into public clouds. Cloud providers can secure the underlying infrastructure, but customers remain responsible for areas such as identity permissions, credentials, application security, data access policies and many configuration decisions.

A compromised privileged identity or application credential can potentially give an attacker legitimate-looking access to enormous datasets without requiring an exploit against the underlying cloud platform.

Healthcare information remains valuable long after a breach

The potential consequences also extend beyond conventional identity theft. Medical and insurance information can support highly personalized fraud because attackers may know details that victims reasonably expect only healthcare providers to possess.

A criminal could potentially combine a person’s name, date of birth, insurance information and medical history to construct convincing communications impersonating insurers, hospitals or medical billing departments. Financial and government identifiers can further increase the credibility and potential impact of those attacks.

Healthcare data also has an unusually long useful life for criminals. Credit cards can be canceled and passwords changed, but historical medical information and many identity attributes remain associated with an individual permanently.

Third-party providers are becoming critical healthcare attack surfaces

The Aesto Health breach ultimately illustrates how the architecture of modern healthcare has changed the meaning of a security perimeter.

Medical information no longer resides exclusively inside hospitals. It moves between EHR platforms, billing providers, cloud environments, laboratories, insurance systems, migration companies and archival services. Every organization participating in that ecosystem can become part of the security boundary protecting patient information.

For attackers, this creates an obvious incentive: instead of compromising healthcare organizations individually, target the technology providers that aggregate information from many of them.

With 9.54 million individuals affected through a single incident, Aesto Health demonstrates the scale that this concentration can produce. The breach is therefore not simply another case of stolen healthcare records. It is another reminder that some of the most consequential targets in healthcare cybersecurity are increasingly the companies operating between healthcare providers rather than the hospitals themselves.

⁠Original report at SecurityWeek

Key facts

  • Personal and health information was stolen from Aesto's AWS infrastructure
  • Approximately 9.5 million individuals were impacted by the data breach
  • The breach targeted a healthcare technology company

Why it matters

This incident highlights the ongoing vulnerability of healthcare data stored in cloud environments. The sheer volume of impacted individuals and the sensitive nature of the stolen information underscore the critical need for robust security measures within cloud infrastructure, particularly for companies handling protected health information. Regulatory scrutiny and potential financial penalties are likely consequences for Aesto, while other healthcare tech providers may face increased pressure to audit their own cloud security postures.