482/69 Thursday, September 3, 2026
Aesto Health, a U.S.-based healthcare technology company, disclosed a data breach affecting the personal and health information of more than 9.5 million people after attackers gained access to parts of the company’s infrastructure on Amazon Web Services (AWS). Aesto Health provides services for managing and protecting Electronic Health Records (EHRs) and legacy medical data for healthcare providers, including secure data migration, EHR data exchange, and long-term data storage.
The company stated that it detected a network security incident around December 18, 2025, affecting a limited portion of its AWS infrastructure. It then launched an investigation with external cybersecurity experts and conducted a detailed review of the relevant documents. The investigation confirmed on May 26, 2026, that between December 2 and December 18, 2025, an unauthorized individual may have accessed or obtained patients’ protected health information belonging to several covered entity healthcare clients, which was stored within Aesto’s network.
The potentially affected information includes names, dates of birth, medical information, health insurance information, driver’s license numbers, government-issued identification numbers, financial account details, taxpayer IDs, and, in some cases, Social Security numbers (SSNs). Aesto stated that it has not found evidence of identity theft or financial fraud related to the incident. The company began notifying affected healthcare clients on June 26, 2026, implemented additional measures to strengthen security, established a dedicated hotline for inquiries, and reported the incident to the U.S. Department of Health and Human Services (HHS), listing 9,540,683 affected individuals.
