Aesto Health breach affects 9.5 million patients, including medical and financial data

Aesto Health, a healthcare SaaS provider, reported a data breach affecting over 9.5 million individuals, with sensitive information including names, medical records, and Social Security numbers exposed. The intrusion occurred between December 2 and 18, 2025, and was confirmed on May 26, 2026, after a forensic investigation. The company is offering 24-month identity theft protection to affected patients.
EXPANDED:
The intrusion targeted Aesto's Amazon Web Services environment, with unauthorized access persisting for roughly two and a half weeks in December 2025. The company confirmed the compromise in late May 2026 after an external forensic review, publicly disclosed it in late June, and began notifying affected individuals in August. No threat group has yet claimed responsibility for the attack.
Beyond the 9.5 million directly affected patients, the incident reaches 29 healthcare organizations that relied on Aesto's data migration and archival services, including VillageMD, Everside Health, and Together Women's Health. Exposed records combine medical information with financial identifiers such as Social Security numbers and taxpayer ID numbers, prompting the company to arrange 24-month credit monitoring through Experian. The breach follows