Egidio
Case file · September 7, 2026

Aesto Health: 9.5 million patients hit through a vendor they never picked

A December 2025 intrusion into Aesto Health's AWS infrastructure has been confirmed to affect 9,540,683 patients across 29 healthcare providers who relied on the vendor — none of whom were breached directly. Confirmed by the company's own federal filing. No attacker has claimed it.

Protect my phone with Egidio Free for calls · 100% on your phone · no account needed
⚠️ Read this before anything else. This breach is confirmed by the company itself, in a filing with a federal regulator — not a hacker claim. What stays open is the usual gap around any vendor breach: how long it went unnoticed, and whether every affected provider has been named.

The numbers, and their real status

9,540,683
Individuals affected, per Aesto Health's own filing with the US Department of Health and Human Services.
BleepingComputer, citing the HHS breach portal. Accessed 09/07/2026.
Dec 2–18, 2025
Window during which an unauthorized actor accessed Aesto's AWS infrastructure — over two months before the company confirmed it internally.
HIPAA Journal.
29
Healthcare provider clients affected — including VillageMD, Everside Health, Marana Health and Together Women's Health — none of whom were breached directly.
SecurityWeek.
?
Attacker identity. As of this page's publication, no group has claimed the breach — this is a confirmed incident with an unknown author.
As of 09/07/2026 — no claim identified.

Timeline

CONFIRMED
December 2–18, 2025
An unauthorized actor accesses a portion of Aesto Health's AWS infrastructure and may have accessed or acquired protected health information.
CONFIRMED
May 26, 2026
Aesto Health confirms internally, after forensic investigation and manual document review, that the intrusion may have exposed patient data — more than five months after the access window closed.
CONFIRMED
June 24, 2026
Aesto notifies its 29 healthcare provider clients, who did not themselves suffer any intrusion — the breach happened entirely on Aesto's side.
CONFIRMED
August 21, 2026
Individual notification letters go out, offering 24 months of Experian IdentityWorks — credit monitoring, identity restoration and identity theft insurance.
CONFIRMED
Early September 2026
HHS posts the figure of 9,540,683 individuals on its public breach portal, making this the second-largest confirmed US healthcare breach reported in 2026.

🏥Why this one matters beyond the number

Aesto Health isn't a hospital, and none of its 9.5 million affected patients chose it. Aesto migrates and archives patient records when a clinic switches electronic-health-record systems or gets acquired — the kind of back-office vendor whose name a patient never hears. The breach surface is one company; the affected population is however many practices handed it their old records. It's the same structural risk documented in CareCloud.

What was exposed

Full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer identification numbers, other government identification numbers, and Social Security numbers — the exact combination varied by individual.

🔒 If you were ever a patient at one of Aesto's 29 provider clients, your data may be included even if you've never heard of Aesto Health. Watch for calls or messages citing a medical record, an insurance claim or a past visit to demand payment or verification — no legitimate provider asks for that by phone.

Frequently asked questions

Is this breach confirmed?

Yes. Aesto Health reported it directly to the US Department of Health and Human Services, and the figure of 9,540,683 individuals comes from that federal filing, not from a hacker claim.

Why haven't I heard of Aesto Health?

Aesto is a back-office vendor that hospitals and clinics use to migrate or archive patient records — patients themselves never interact with it directly.

What should affected patients do?

Aesto is offering 24 months of Experian IdentityWorks (credit monitoring, identity restoration, identity theft insurance) to affected individuals via notification letters sent from August 21, 2026.

📌 Last checked: September 7, 2026. Verifiable correction: contact@egidio.app.

Read next

Cite this page Egidio — Threat Laboratory, « Aesto Health: 9.5 million patients hit through a vendor they never picked », egidio.app/en/laboratoire/aesto-health-vendor-breach/. CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.

Sources. Primary record: HHS Office for Civil Rights breach portal. Reporting: BleepingComputer, SecurityWeek and HIPAA Journal, all citing the same HHS filing. Checked 09/07/2026.