news.mlab.sh
Back to the feed
data-breach

9.5 Million Impacted by Aesto Health Data Breach

High
Summary

Aesto Health, a healthcare technology company, suffered a data breach exposing the personal and health information of nearly 10 million people. The breach occurred due to unauthorized activity within their AWS infrastructure, leading to the theft of sensitive data including Social Security numbers and medical records. The company notified the HHS and impacted numerous healthcare providers across several states. This incident highlights the ongoing risk of data breaches within the healthcare sector.

Aesto Health, a healthcare technology company based in Birmingham, Alabama, experienced a significant data breach compromising the personal and health information of nearly 10 million individuals. The breach was discovered on December 18, 2025, and involved unauthorized activity within Aesto Health’s Amazon Web Services (AWS) infrastructure.

According to a June 2026 incident notice, the company’s investigation determined that hackers exfiltrated personally identifiable information (PII) and protected health information (PHI) between December 2 and 18, 2025. The compromised data included names, Social Security numbers, driver’s license numbers, other ID numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers.

Aesto Health has notified the US Department of Health and Human Services (HHS) that 9,540,683 individuals are impacted by the data breach. At least two dozen Aesto Health healthcare provider clients across several states have been affected by the incident, with some of these clients proactively notifying the potentially affected individuals themselves.

The company’s investigation revealed that the breach stemmed from unauthorized activity within their AWS environment. The incident has been added to the HHS data breach portal.

Read the full article at SecurityWeek