Aesto Health AWS breach exposes 9.54M patient records

Aesto Health reports an AWS breach exposed personal and medical data for 9,540,683 people; data was exfiltrated Dec. 2–18, 2025.
Aesto Health, a Birmingham, Alabama–based vendor that provides secure data migration, electronic health record exchanges and legacy data archiving for health providers, reported an Amazon Web Services infrastructure breach that exposed personal and medical information for 9,540,683 people. The company detected unauthorized activity on Dec. 18, 2025, and disclosed the incident in a June 2026 notice.
Aesto’s investigation, completed May 26, 2026, found data was taken between Dec. 2 and Dec. 18, 2025. In its notice the company said, “Upon detecting the unauthorized activity, we immediately contained the incident and commenced a thorough investigation. As part of our investigation, we engaged leading cybersecurity experts to identify what personal information, if any, was involved.” The firm reported portions of its AWS environment had been compromised.
The review determined both personally identifiable information and protected health information were removed. Compromised items listed by the company include names, Social Security numbers, driver’s license and other identification numbers, dates of birth, financial account numbers, medical information, health insurance details and taxpayer identification numbers.
Aesto notified the U.S. Department of Health and Human Services and was added to HHS’s public breach reporting portal. The company reported 9,540,683 individuals affected. At least two dozen of Aesto’s healthcare provider clients in multiple states were impacted; some provider organizations have issued their own notifications to potentially affected patients.
Aesto Health said its investigation is ongoing. The company has not disclosed how attackers gained access to the AWS environment, whether any ransom demands were made, or what specific mitigation or identity protection services, if any, it is offering to affected individuals. Provider clients may issue additional details about exposures and remediation options as they complete their own reviews.








