Aesto Health: 9.5 million patients hit through a vendor they never picked
A December 2025 intrusion into Aesto Health's AWS infrastructure has
been confirmed to affect 9,540,683 patients across 29 healthcare
providers who relied on the vendor — none of whom were breached directly. Confirmed by
the company's own federal filing. No attacker has claimed it.
⚠️ Read this before anything else. This breach
is confirmed by the company itself, in a filing with a federal regulator — not a hacker
claim. What stays open is the usual gap around any vendor breach: how long it went
unnoticed, and whether every affected provider has been named.
The numbers, and their real status
9,540,683
Individuals affected, per Aesto Health's own filing with the US
Department of Health and Human Services.
BleepingComputer, citing the HHS breach portal. Accessed 09/07/2026.
Dec 2–18, 2025
Window during which an unauthorized actor accessed Aesto's AWS
infrastructure — over two months before the company confirmed it internally.
Healthcare provider clients affected — including VillageMD, Everside
Health, Marana Health and Together Women's Health — none of whom were breached directly.
Attacker identity. As of this page's publication, no group has
claimed the breach — this is a confirmed incident with an unknown author.
As of 09/07/2026 — no claim identified.
Timeline
CONFIRMED
December 2–18, 2025
An unauthorized actor accesses a portion of Aesto Health's AWS
infrastructure and may have accessed or acquired protected health information.
CONFIRMED
May 26, 2026
Aesto Health confirms internally, after forensic investigation and
manual document review, that the intrusion may have exposed patient data — more than
five months after the access window closed.
CONFIRMED
June 24, 2026
Aesto notifies its 29 healthcare provider clients, who did not
themselves suffer any intrusion — the breach happened entirely on Aesto's side.
CONFIRMED
August 21, 2026
Individual notification letters go out, offering 24 months of
Experian IdentityWorks — credit monitoring, identity restoration and identity theft
insurance.
CONFIRMED
Early September 2026
HHS posts the figure of 9,540,683 individuals on its public breach
portal, making this the second-largest confirmed US healthcare breach reported in 2026.
🏥Why this one matters beyond the number
Aesto Health isn't a hospital, and none of its 9.5 million affected patients chose it.
Aesto migrates and archives patient records when a clinic switches electronic-health-record
systems or gets acquired — the kind of back-office vendor whose name a patient never hears.
The breach surface is one company; the affected population is however many practices handed
it their old records. It's the same structural risk documented in
CareCloud.
What was exposed
Full names, dates of birth, medical information, driver's license numbers, financial
account numbers, health insurance information, taxpayer identification numbers, other
government identification numbers, and Social Security numbers — the exact combination varied
by individual.
🔒 If you were ever a patient at one of Aesto's 29 provider clients,
your data may be included even if you've never heard of Aesto Health. Watch for calls or
messages citing a medical record, an insurance claim or a past visit to demand payment or
verification — no legitimate provider asks for that by phone.
Frequently asked questions
Is this breach confirmed?
Yes. Aesto Health reported it directly to the US Department of Health and Human Services,
and the figure of 9,540,683 individuals comes from that federal filing, not from a hacker
claim.
Why haven't I heard of Aesto Health?
Aesto is a back-office vendor that hospitals and clinics use to migrate or archive patient
records — patients themselves never interact with it directly.
What should affected patients do?
Aesto is offering 24 months of Experian IdentityWorks (credit monitoring, identity
restoration, identity theft insurance) to affected individuals via notification letters sent
from August 21, 2026.
📌 Last checked: September 7, 2026. Verifiable
correction: contact@egidio.app.
Cite this pageEgidio — Threat Laboratory, « Aesto Health: 9.5 million patients hit through a vendor they never picked », egidio.app/en/laboratoire/aesto-health-vendor-breach/. CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.