Aesto Health data breach (2026): what was exposed and what to do

Updated Corrections

September 16, 2026

We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.

What happened

Aesto Health (Aesto, LLC), a Birmingham, Alabama company that migrates and archives medical records for healthcare providers, said an unauthorized actor accessed a limited portion of its Amazon Web Services environment between about December 2 and December 18, 2025. Aesto detected the activity around December 18, contained it, and on May 26, 2026 confirmed through a forensic review that patient information belonging to its provider clients may have been accessed or taken. It posted a public notice on June 24, 2026 and began notifying its provider clients on June 26.

On July 31, 2026, Aesto reported the breach to the U.S. Department of Health and Human Services as affecting 9,540,683 people, which HIPAA Journal called the second-largest confirmed healthcare data breach of 2026 so far. Aesto's list of affected clients names 28 healthcare organizations, and other providers have filed their own notices with state attorneys general. State filings show the spread: South Carolina lists 80,622 residents for one client, Everside Health; Washington lists more than 58,000 residents across two clients; Oregon lists 731; and Vermont lists 91. BleepingComputer reported that patient notices began going out on August 21, and no hacking group has publicly claimed the attack.

Because Aesto works on behalf of healthcare providers, your notice letter may come from your own hospital, clinic, or health system rather than from Aesto.

Sources

What data was exposed

The following types of personal data were compromised:

  • Full names
  • Dates of birth
  • Medical information
  • Health insurance information
  • Driver's license numbers and other government ID numbers
  • Financial account numbers
  • Social Security numbers and individual taxpayer identification numbers (for a limited number of people, per Aesto)

Breach details

Detail Value
Breach name Aesto Health
Date December 2 to 18, 2025
Disclosed June 24, 2026
Accounts affected 9,540,683 (reported to HHS)
Domain aestohealth.com

This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.

We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Aesto Health; it reflects a publicly reported security incident.

For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.

What to do now

Based on the data exposed in this breach, here are the steps you should take:

  • Place a free credit freeze with Equifax, Experian, and TransUnion. Aesto said Social Security numbers, driver's license numbers, and financial account numbers were involved for some people.
  • Review Explanation of Benefits statements and insurance claims for care you did not receive. Medical identity theft can surface months after a breach.
  • Treat emails or calls that name your clinic or hospital and ask you to "confirm" insurance or Social Security details as likely phishing. Use contact details from your provider's website or your mailed notice.
  • Check bank statements for charges or transfers you don't recognize, and report them to your bank right away.
  • If you have questions about a notice, call the Aesto assistance line listed in its public notice (833-918-8060, engagement number B167683, Monday to Friday, 8am to 8pm Central).

What to do after a breach

A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.

More breaches

Free personal data exposure scan

We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.