2025–2026 Aesto Health — AWS PHI incident Dec 2–18 2025; 9.54M individuals (HHS)
Data compromised
Full names, SSNs, driver’s license / state ID numbers, full or partial dates of birth; health records, medical histories, health insurance policy numbers, and claims/billing information for some provider patients
Technical writeup
Verified company and HHS OCR census — September 1, 2026. Aesto Health (Birmingham, AL healthcare data-migration/archive SaaS vendor) confirmed unauthorized access to a limited AWS environment between December 2 and December 18, 2025; forensics confirmed May 26, 2026. BleepingComputer and HIPAA Journal report Aesto filed with HHS that 9,540,683 individuals were affected — names, DOBs, medical information, driver’s licenses, financial account numbers, health insurance, taxpayer/government IDs, and Social Security numbers. The breach indirectly impacts dozens of covered-entity clients (reporting cites VillageMD, Everside/Marathon Health, Marana Health, Together Women’s Health among others). Patient letters began August 21, 2026 with 24-month Experian monitoring (833-918-8060). recordsAffected 9540683 from HHS filing via BleepingComputer; companyConfirmed true.
Root cause
Unauthorized access to a limited portion of Aesto Health Amazon Web Services infrastructure (company notice; Dec 2–18, 2025 window confirmed May 26, 2026)
References
- https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/
- https://www.aestohealth.com/notice-of-data-security-incident-12-18-25/
- https://www.hipaajournal.com/aesto-health-data-breach/
- https://oag.ca.gov/ecrime/databreach/reports/sb24-627495
- https://ago.vermont.gov/categories/security-breach-notices
- https://www.claimdepot.com/data-breach/aesto-health-2026