Aesto LLC, operating as Aesto Health, disclosed a significant data breach affecting more than 9.5 million individuals. The breach was discovered recently and reported publicly. The incident represents one of the larger healthcare data breaches in terms of patient count. Healthcare data breaches are particularly sensitive due to the nature of personal and medical information involved. The scale of the breach places it among the more impactful incidents in the healthcare sector. Further details about the nature of the compromised data and the attack vector were not fully elaborated in the article excerpt. Regulatory notifications and patient advisories are likely underway given the magnitude of the breach.
Aesto Health (Aesto LLC) suffered a data breach affecting its Amazon Web Services (AWS) infrastructure. The intrusion occurred between approximately December 2, 2025, and December 18, 2025, during which an unauthorized actor accessed and/or acquired protected health information (PHI) stored within Aesto's network. The breach was confirmed internally on May 26, 2026, following a forensic investigation conducted by external specialists. Only a 'limited portion' of the AWS infrastructure was reportedly compromised. Aesto provides SaaS solutions for healthcare organizations to migrate, archive, and access patient data during EHR system replacements or medical practice acquisitions. A total of 9,540,683 individuals were impacted, and 29 downstream healthcare providers were indirectly affected, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women's Health. Compromised data types include: full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. No threat group has publicly claimed responsibility for the attack.
1. Impacted individuals should enroll in the 24-month identity theft protection and credit monitoring service offered by Aesto Health through Experian. 2. Monitor financial accounts and health insurance statements for signs of fraud or unauthorized activity. 3. Consider placing a credit freeze or fraud alert with major credit bureaus. 4. Healthcare organizations using Aesto Health or similar SaaS vendors should review third-party vendor access controls and security posture. 5. Conduct thorough forensic investigations if unauthorized access to AWS infrastructure is suspected. 6. Implement monitoring and alerting for abnormal data access patterns within cloud environments. 7. Healthcare providers should notify affected patients promptly as required under HIPAA breach notification rules. 8. Report any suspicious activity related to the breach to the U.S. Department of Health and Human Services (HHS) as appropriate.