In a significant cybersecurity incident, Aesto Health, a healthcare technology company based in Birmingham, Alabama, has experienced a data breach that compromised the personal and health information of over 9.5 million individuals. This breach highlights growing concerns about data security in the healthcare sector.
Details of the Aesto Health Breach
Aesto Health is known for providing secure data migration, electronic health record (EHR) exchanges, and legacy data archiving services. The company disclosed in a June 2026 notice that it discovered unauthorized access to parts of its Amazon Web Services (AWS) infrastructure on December 18, 2025. This breach affected the security of sensitive information.
Upon identifying the breach, Aesto Health took immediate action to contain the situation and initiated an in-depth investigation. They collaborated with leading cybersecurity experts to assess the extent of the breach and determine the specific data involved.
Impact and Scope of Compromised Information
By May 26, 2026, Aesto Health concluded that hackers had accessed and exfiltrated personally identifiable information (PII) and protected health information (PHI) between December 2 and 18, 2025. The stolen data encompasses names, Social Security numbers, driver’s license numbers, various ID numbers, dates of birth, financial account details, medical information, health insurance data, and taxpayer identification numbers.
The U.S. Department of Health and Human Services (HHS) has been informed about the breach, which affects 9,540,683 individuals. Consequently, Aesto Health has been listed on the HHS data breach portal as part of the ongoing response to this incident.
Response and Future Implications
At least two dozen healthcare providers, who are clients of Aesto Health across multiple states, have been impacted by this breach. Some of these providers have opted to directly inform individuals potentially affected by the incident, underscoring the widespread repercussions of the breach.
This incident serves as a critical reminder of the vulnerabilities in healthcare data systems and the importance of robust cybersecurity measures. As breaches become increasingly sophisticated, companies like Aesto Health must prioritize data protection to prevent future incidents.
In the wake of this breach, stakeholders in the healthcare industry are urged to reassess their cybersecurity frameworks and ensure the protection of sensitive information to build trust and maintain compliance with regulatory standards.
