Aesto Health Data Breach Affects Over 9.5 Million Patients

September 1, 2026

Healthcare technology company Aesto Health has reported a major data breach potentially affecting 9,540,683 individuals.

According to Aesto, an unauthorized actor accessed a portion of its AWS infrastructure between December 2 and December 18, 2025. The company detected the incident on December 18 and launched an investigation with the help of external cybersecurity experts.

The investigation found that personal and protected health information belonging to patients of Aesto's healthcare-provider clients may have been accessed or acquired.

What Information Was Exposed?

The potentially affected information varied by individual and may have included:

  • Names and dates of birth

  • Medical and health insurance information

  • Social Security numbers

  • Government identification numbers

  • Driver's license information

  • Financial account information

Aesto has stated that it currently has no evidence of identity theft or financial fraud connected to the incident.

The Cybersecurity Risk

The incident highlights the growing threat of third-party data breaches in healthcare. Patients may have never directly interacted with Aesto, but their information was processed or stored through the company's services.

The breach also demonstrates that organizations using cloud infrastructure such as AWS must properly secure their own accounts, systems and data.

Aesto has notified affected organizations and individuals and has recommended measures such as credit monitoring and reviewing financial and healthcare accounts for suspicious activity.

Key takeaway: Healthcare organizations must secure not only their own systems but also the third-party vendors that handle sensitive patient information.

Source: Aesto Health, HHS, BleepingComputer


Follow us on X , Facebook

Comments

Popular posts from this blog

Apollo Global Management Data Breach: When Hackers Target People, Not Just Systems

BlackRock Scam Explained: How a Telecom Giant Fell for a Phishing & Investment Fraud

New Call Forwarding Scam in India: How Fraudsters Can Steal Your OTPs Without Asking for an OTP