
AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
An unauthorised party had access to part of the health-data archiving firm's AWS environment for about 16 days in December 2025. It reported 9,540,683 people to HHS.
What happened
Aesto Health, a Birmingham, Alabama company that migrates and archives medical records for healthcare providers, says it detected a security incident on or about 18 December 2025 affecting part of its Amazon Web Services (AWS) infrastructure. According to its website notice, a forensic review completed on 26 May 2026 found that an unauthorised actor may have accessed or acquired patient data between about 2 and 18 December 2025. Aesto began notifying its provider clients on 26 June 2026. The HIPAA Journal and SecurityWeek report that the breach was reported to the US Department of Health and Human Services (HHS) as affecting 9,540,683 people.
Confirmed vs. claimed
Confirmed by Aesto: the dates of access and the data types, which vary by person and include names, dates of birth, medical and health insurance information, driver's licence numbers, financial account numbers, taxpayer ID numbers and Social Security numbers. Aesto says it has no evidence of identity theft or fraud linked to the incident.
Not disclosed: how the attacker got in, and whether any group has claimed the attack. No group has publicly taken credit in the sources we reviewed. The HIPAA Journal counts at least 38 affected provider clients.
Who is affected
Patients of Aesto's US healthcare provider clients. Because some clients are sending their own letters, a notice may come from your doctor or hospital rather than from Aesto.
What to do
- Read any letter carefully and enrol in the credit monitoring and identity protection offered.
- Place a fraud alert or credit freeze with the US credit bureaus.
- Check insurance explanation-of-benefits statements for care you did not receive.
- Be wary of calls claiming to be from your provider or insurer that ask you to confirm details.
- See our guide on what to do after a data breach notice.
Sources
More breaches in United States
- IDScan.net — 01 Sep 2026
- Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) — 27 Aug 2026
- Boston Scientific — 26 Aug 2026
- DentaQuest — 17 Jul 2026
- Abbott (Exact Sciences) — 16 Jul 2026