Attackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million Records
Attackers accessed part of Aesto Health's AWS infrastructure between December 2-18, 2025, exposing personal and health data of over 9.5 million patients.
Aesto Health, a Birmingham, Alabama healthcare technology company, disclosed a breach affecting 9,540,683 individuals whose protected health information was stored in its AWS infrastructure. Attackers had access from around December 2 to December 18, 2025; the incident was discovered on December 18, 2025 and confirmed on May 26, 2026 after a forensic investigation. Exposed data may include names, birth dates, medical and insurance details, financial account information, government ID numbers and, for a limited number of people, Social Security numbers. Aesto reported the incident to HHS and says it found no evidence of identity theft or financial fraud.
- Attackers accessed a limited portion of Aesto Health's AWS infrastructure for over two weeks
- HHS notified; breach impacted 9,540,683 individuals across multiple healthcare clients
- Data includes names, birth dates, insurance and medical info, financial account details, some SSNs
- Company launched an external forensic investigation and set up a dedicated helpline
Full article389 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 01, 2026

Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure.
Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, after attackers gained access to part of its Amazon Web Services infrastructure.
Aesto Health is a U.S. healthcare technology company based in Birmingham, Alabama. It helps healthcare providers manage and protect electronic health records and other legacy medical data. Its services include secure data migration, electronic health record (EHR) exchanges and long-term data archiving. Aesto works with medical practices and healthcare organizations that need to move, store or access patient information securely.
“On or about December 18, 2025, Aesto experienced a network security incident that impacted a limited portion of our Amazon Web Services infrastructure.” reads the Notice of Data Security Incident. “After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor.”
The company launched an investigation into the incident with external leading cybersecurity experts.
The network security incident affected part of its Amazon Web Services infrastructure between December 2 and 18, 2025. On May 26, 2026, Aesto confirmed that an unauthorized actor may have accessed or acquired protected health information stored in its network. Exposed data may include names, birth dates, medical and insurance information, driver’s license and government ID numbers, financial account details, taxpayer IDs and, for a limited number of people, Social Security numbers.
Aesto says it found no evidence of identity theft or financial fraud linked to the breach. Starting June 26, 2026, it notified affected healthcare clients whose patients’ data may have been accessed.
The company announced it has already implemented measures to strengthen security and set up a dedicated helpline for questions.
The healthcare firm also notified the US Department of Health and Human Services (HHS), reporting that the incident impacted 9540683 individuals.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Aesto Health)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/198250/data-breach/attackers-access-aesto-health-aws-infrastructure-exposing-9-5-million-records.html