9.5 Million People Affected in Aesto Health Data Breach

www.news4hackers.com-9-5-million-people-affected-in-aesto-health-data-breach-9-5-million-people-affected-in-aesto-health-data-breach

Aesto Health’s data breach exposed 9.5 million individuals’ personal and medical records due to unauthorized access in their AWS infrastructure.

Breach Overview

More than 9.5 million individuals experienced a data breach involving their personal and medical records following an unauthorized access incident at Aesto Health. The Birmingham, Alabama-based company, which provides data migration solutions, electronic health record (EHR) exchange platforms, and legacy data archiving services to healthcare organizations, disclosed the breach in a public notice dated June 2026.

Timeline and Discovery

The compromise was identified on December 18, 2025, and involved unauthorized activity within its Amazon Web Services (AWS) infrastructure. Upon detecting the breach, the organization initiated containment measures and conducted a comprehensive investigation with cybersecurity specialists to determine the scope of affected data. On May 26, 2026, the findings confirmed that attackers exfiltrated sensitive information between December 2 and 18, 2025.

Data Exposed

The stolen data includes names, Social Security numbers, driver’s license details, financial account numbers, medical histories, health insurance information, taxpayer identification numbers, and dates of birth.

Response and Reporting

Aesto Health reported the incident to the U.S. Department of Health and Human Services (HHS), which listed the breach on its public portal. The company confirmed that at least 24 healthcare provider clients across multiple states were impacted. Some of these clients have independently informed their patients about the potential exposure.

Security Implications

The breach highlights vulnerabilities in cloud infrastructure management, as the compromise occurred within AWS environments. The timeline indicates a prolonged period of unauthorized access, raising concerns about detection mechanisms and response protocols. Affected individuals may face risks such as identity theft, financial fraud, and medical identity exploitation. No details about the attackers or methods used to breach the system were disclosed. The incident underscores the importance of robust cloud security practices, continuous monitoring, and timely incident response in healthcare technology ecosystems.



About Author

en_USEnglish