Skip to content
Tech News
← Back to articles

Aesto Health says data breach affects over 9.5 million patients

read original more articles
Why This Matters

The Aesto Health data breach, impacting over 9.5 million individuals, highlights the ongoing vulnerabilities within healthcare data management systems and the critical need for robust cybersecurity measures. This incident underscores the importance for both tech providers and consumers to prioritize data security, especially given the sensitive nature of health information. As healthcare organizations increasingly rely on SaaS solutions, ensuring the integrity and protection of patient data remains a top industry concern.

Key Takeaways

Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals.

The private technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices.

The company first informed the public of the attack on June 24 via a notification on its website, stating that “a limited portion” of its Amazon Web Services infrastructure had been compromised.

However, the intrusion occurred in December 2025 and was confirmed internally on May 26, following a forensic investigation by external specialists.

“After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor,” reads the statement.

In a report to the U.S. Department of Health and Human Services, Aesto Health said that the data breach affects 9,540,683 individuals.

“The information included full names, dates of birth, medical information, driver’s license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers.”

HIPAA Journal says that the incident indirectly impacts 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women’s Health.

On August 21, the company started to inform impacted individuals of the data breach, providing details about the incident and instructions on how to enroll in a 24-month identity theft protection and credit monitoring service through Experian.

The Aesto Health data breach follows a series of similar incidents at other healthtech software companies, including iRhythm, Xolis, Medronic, MCBS, Health-ISAC, Unlimited Technology Systems, CareCloud, Nutex Health, and McKesson.

... continue reading