Aesto LLC, operating under the name Aesto Health, has disclosed a healthcare data breach that may have exposed the sensitive information of more than 9.5 million individuals.
Aesto Health is a private technology company that provides software-as-a-service solutions for healthcare organizations. Its platforms help providers migrate, archive, and access patient records when replacing electronic health record systems or acquiring medical practices.
The company first disclosed the incident on June 24 in a notice published on its website. Aesto Health said that a “limited portion” of its Amazon Web Services infrastructure had been compromised.
According to the company, the cyberattack occurred in December 2025. Aesto Health confirmed the incident on May 26, 2026, following a forensic investigation conducted with the assistance of external cybersecurity experts.
“After extensive forensic investigation and manual document review, we have determined that on or about May 26, 2026, December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or obtained by an unauthorized attacker,” the company said in its data security incident notice.
In a report submitted to the U.S. Department of Health and Human Services, Aesto Health stated that the data breach affected 9,540,683 individuals.
The compromised information may have included names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance details, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers.
According to HIPAA Journal, the breach indirectly affected 29 healthcare providers, including VillageMD, Everside Health, Marathon Health, Marana Health, and Together Women’s Health.
On August 21, Aesto Health began notifying affected individuals about the incident. The notification letters reportedly include details about the breach and instructions for enrolling in 24 months of identity theft protection and credit monitoring services provided through Experian.
The Aesto Health data breach is the latest in a series of cybersecurity incidents involving healthcare technology providers. Similar breaches have recently impacted companies including iRhythm, Xolair, Medtronic, MCBS, Health-ISAC, Unlimited Technology Systems, CareCloud, Nutex Health, and McKesson.
As of this writing, no known threat group has publicly claimed responsibility for the attack against Aesto Health.
The overall prevention score can hide what happens after an attacker gains initial access. When threat actors use valid credentials, security defenses can become significantly less effective.
The Blue Report 2026 measures defensive techniques across different technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com



