Contained High impact Data breach Checked 1d ago

Aesto Health breach exposes 9.5 million patient records

Aesto Health found unauthorized activity in its Amazon cloud infrastructure in December 2025 and later confirmed an attacker accessed or took patient data. The company has reported 9,540,683 affected people to federal health regulators, making it one of the largest healthcare breaches disclosed this year. Follow-up reporting shows the breach reached at least 35 of Aesto's healthcare provider clients, since Aesto is a vendor that manages patient data for other medical organizations. Aesto says it has found no evidence the stolen data has been used for identity theft or fraud so far.

Started
Dec 1, 2025
Latest activity
Sep 10, 2026
Attributed to
Not confirmedNo credible attribution yet
Where
United States
Sectors
Healthcare
Scale
Aesto Health, a healthcare data management vendor, and at least 35 of its healthcare provider clients, covering 9.5 million patients

Current status

On September 10, 2026, AWKO Law LLP announced an investigation into the breach. No new attacker activity or additional victims were reported.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Impact

Names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance details, taxpayer ID numbers and Social Security numbers were exposed.

What to do

Affected patients should watch for the breach notification letter, enroll in the free credit monitoring Aesto Health is offering, and watch bank and insurance statements for unfamiliar activity.

Timeline

  1. Sep 10, 2026

    AWKO Law LLP announced an investigation into the Aesto Health breach. The announcement reported no new attacker activity or additional victims.

    Containedrutlandherald.com
  2. Sep 2, 2026

    Aesto Health reported 9,540,683 affected individuals to the US Department of Health and Human Services.

    Containedyahoo.com
  3. Sep 1, 2026

    Follow-up reporting clarified that the breach reached at least 35 of Aesto Health's healthcare provider clients, since Aesto acts as a data management vendor for other medical organizations rather than treating patients directly.

    Containedhipaajournal.com
  4. Jun 24, 2026

    Aesto Health publicly disclosed the incident without revealing its full scope.

    Containedesecurityplanet.com
  5. Dec 1, 2025

    Aesto Health detected unauthorized activity in its AWS infrastructure.

    Emergingesecurityplanet.com

Sources

Related reports