2026 Aesto Health — AWS vendor PHI incident Dec 2–18 2025; CA/VT AG notices (count TBD)
Data compromised
Full names, SSNs, driver’s license / state ID numbers, full or partial dates of birth; health records, medical histories, health insurance policy numbers, and claims/billing information for some provider patients
Technical writeup
Verified — Aesto Health (Birmingham, AL) website notice of data security incident and California / Vermont AG filings (reported July 31, 2026). As a third-party healthcare data manager, Aesto said a limited portion of its AWS environment was involved; forensics confirmed that between on or about Dec. 2 and Dec. 18, 2025 a limited amount of PHI/PII on its network may have been accessed or acquired. The company notified an affected healthcare provider on June 26, 2026 and began mailing individuals. Vermont AG materials identify 91 Vermont residents; no nationwide total was published at indexing, so recordsAffected is 0. Complimentary Privacy Solutions ID monitoring via Epiq; response line 833-918-8060.
Root cause
Unauthorized access to a limited portion of Aesto Health Amazon Web Services infrastructure (company notice; Dec 2–18, 2025 window confirmed May 26, 2026)