Aesto Health reports 9.5 million patient data breach
A healthcare technology company has disclosed that a cyberattack last December resulted in the exposure of sensitive personal and health information for more than 9.5 million individuals. Aesto Health, based in Birmingham, Alabama, informed federal regulators this week that the breach affected data belonging to patients of its client healthcare organizations. The intrusion occurred between December 2 and December 18, 2025, when unauthorized actors gained access to a portion of Aesto Health's Amazon Web Services infrastructure. The company confirmed the extent of the breach on May 26, 2026, following an extensive forensic investigation. The stolen data includes full names, dates of birth, medical information, drivers license numbers, financial account numbers, health insurance data, taxpayer identification numbers, and for some individuals, Social Security numbers. Aesto Health, which provides data migration, archiving, and electronic health record services to medical facilities, first alerted the public to a potential compromise in June 2026.