Aesto Health Data Breach Affects Over 9.5 Million Patients
September 1, 2026
Healthcare technology company Aesto Health has reported a major data breach potentially affecting 9,540,683 individuals.
According to Aesto, an unauthorized actor accessed a portion of its AWS infrastructure between December 2 and December 18, 2025. The company detected the incident on December 18 and launched an investigation with the help of external cybersecurity experts.
The investigation found that personal and protected health information belonging to patients of Aesto's healthcare-provider clients may have been accessed or acquired.
What Information Was Exposed?
The potentially affected information varied by individual and may have included:
Names and dates of birth
Medical and health insurance information
Social Security numbers
Government identification numbers
Driver's license information
Financial account information
Aesto has stated that it currently has no evidence of identity theft or financial fraud connected to the incident.
The Cybersecurity Risk
The incident highlights the growing threat of third-party data breaches in healthcare. Patients may have never directly interacted with Aesto, but their information was processed or stored through the company's services.
The breach also demonstrates that organizations using cloud infrastructure such as AWS must properly secure their own accounts, systems and data.
Aesto has notified affected organizations and individuals and has recommended measures such as credit monitoring and reviewing financial and healthcare accounts for suspicious activity.
Key takeaway: Healthcare organizations must secure not only their own systems but also the third-party vendors that handle sensitive patient information.
Source: Aesto Health, HHS, BleepingComputer
Comments
Post a Comment