Aesto Health says data breach affects over 9.5 million patients

Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals.

The private technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices.

The company first informed the public of the attack on June 24 via a notification on its website, stating that “a limited portion” of its Amazon Web Services infrastructure had been compromised.

However, the intrusion occurred in December 2025 and was confirmed internally on May 26, following a forensic investigation by external specialists.

“After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor,” reads the statement.

In a report to the U.S. Department of Health and Human Services, Aesto Health said that the data breach affects 9,540,683 individuals.

“The information included full names, dates of birth, medical information, driver’s license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers.”

HIPAA Journal says that the incident indirectly impacts 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women’s Health.

On August 21, the company started to inform impacted individuals of the data breach, providing details about the incident and instructions on how to enroll in a 24-month identity theft protection and credit monitoring service through Experian.

The Aesto Health data breach follows a series of similar incidents at other healthtech software companies, including iRhythm, Xolis, Medronic, MCBS, Health-ISAC, Unlimited Technology Systems, CareCloud, Nutex Health, and McKesson.

At the time of writing, no threat groups have publicly claimed the Aesto Health attack.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

McKesson discloses breach after ShinyHunters claims patient data theft

Hospital operator Nutex Health says data stolen in cyberattack

Healthtech firm CareCloud data breach impacts 3.7 million patients

Novocure data breach affects more than 1,400 cancer patients

LACMA data breach last year exposed social security and medical data

Massive Microsoft 365 outage causes auth issues, service failures

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Chrome Web Store extensions caught stealing crypto, browser data

Identity, Data Governance & Threat Detection in One Platform: Take our In-Browser Tour

Learn how ESET MDR can enhance your organization’s security posture

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

Can you trust every session? See how session enrichment enables better authentication decisions.

AI-driven vulnerability discovery is accelerating. See how Action1 helps remediation keep pace.

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.