Aesto Health data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
Aesto Health (Aesto, LLC), a Birmingham, Alabama company that migrates and archives medical records for healthcare providers, said an unauthorized actor accessed a limited portion of its Amazon Web Services environment between about December 2 and December 18, 2025. Aesto detected the activity around December 18, contained it, and on May 26, 2026 confirmed through a forensic review that patient information belonging to its provider clients may have been accessed or taken. It posted a public notice on June 24, 2026 and began notifying its provider clients on June 26.
On July 31, 2026, Aesto reported the breach to the U.S. Department of Health and Human Services as affecting 9,540,683 people, which HIPAA Journal called the second-largest confirmed healthcare data breach of 2026 so far. Aesto's list of affected clients names 28 healthcare organizations, and other providers have filed their own notices with state attorneys general. State filings show the spread: South Carolina lists 80,622 residents for one client, Everside Health; Washington lists more than 58,000 residents across two clients; Oregon lists 731; and Vermont lists 91. BleepingComputer reported that patient notices began going out on August 21, and no hacking group has publicly claimed the attack.
Because Aesto works on behalf of healthcare providers, your notice letter may come from your own hospital, clinic, or health system rather than from Aesto.
Sources
- Notice of Data Security Incident, Aesto Health
- Aesto Health Data Breach Affects 9.5 Million Patients, HIPAA Journal
- Notice of Data Security Incident (affected covered entities), Aesto Health
- Breach Portal, U.S. Department of Health and Human Services Office for Civil Rights
- Submitted Breach Notification Sample: Together Women's Health LLC - Aesto, California Attorney General
- Security Breach Notices, South Carolina Department of Consumer Affairs
- Data Security Breaches, Oregon Department of Justice
- Aesto Health says data breach affects over 9.5 million patients, BleepingComputer
- 9.5 Million Impacted by Aesto Health Data Breach, SecurityWeek
- Health data of more than 9.5 million people leaked from Aesto record system, The Record
- Data Breach Notifications, Washington State Office of the Attorney General
- Security Breach Notices, Office of the Vermont Attorney General
What data was exposed
The following types of personal data were compromised:
- Full names
- Dates of birth
- Medical information
- Health insurance information
- Driver's license numbers and other government ID numbers
- Financial account numbers
- Social Security numbers and individual taxpayer identification numbers (for a limited number of people, per Aesto)
Breach details
| Detail | Value |
|---|---|
| Breach name | Aesto Health |
| Date | December 2 to 18, 2025 |
| Disclosed | June 24, 2026 |
| Accounts affected | 9,540,683 (reported to HHS) |
| Domain | aestohealth.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Aesto Health; it reflects a publicly reported security incident.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- Place a free credit freeze with Equifax, Experian, and TransUnion. Aesto said Social Security numbers, driver's license numbers, and financial account numbers were involved for some people.
- Review Explanation of Benefits statements and insurance claims for care you did not receive. Medical identity theft can surface months after a breach.
- Treat emails or calls that name your clinic or hospital and ask you to "confirm" insurance or Social Security details as likely phishing. Use contact details from your provider's website or your mailed notice.
- Check bank statements for charges or transfers you don't recognize, and report them to your bank right away.
- If you have questions about a notice, call the Aesto assistance line listed in its public notice (833-918-8060, engagement number B167683, Monday to Friday, 8am to 8pm Central).
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Got a breach email?
- First 48 hours after a data breach
- Dark web vs. data brokers
- What to do after a data breach
- Veradigm breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.