More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen

Laboratory
(Image credit: Pixabay)

  • Aesto Health reported a December 2025 cyberattack breaching AWS infrastructure, affecting 9.5M patients
  • Stolen data includes PII, SSNs, medical histories, billing, and insurance information across 20+ clients
  • No dark web leaks confirmed; credit monitoring offered, marking 2nd‑largest healthcare breach of 2026

American healthcare technology company Aesto Health suffered the “second-largest confirmed healthcare data breach” of the year so far, having lost data on more than 9.5 million patients.

In mid-December last year, the company suffered a cyberattack. Now, more than half a year later, it reported the incident to the HHS’ Office for Civil Rights, detailing what was lost, from whom, and what the extent of the incident is.

Aesto Health is an Alabama-based healthcare technology business, whose core service is helping other healthcare firms manage medical data, change electronic health record systems, and similar. As per its announcement, the attack affected parts of its Amazon Web Services (AWS) infrastructure, which unidentified threat actors managed to access between December 2 and December 18.

Latest Videos FromTechRadar

Losing personally identifiable information

According to a report on HIPAA Journal, the August attack affected more than two dozen of its clients, including Village Practice Management, Everside Health, Together Women’s Health Medical Group, and many others.

In the attack, the company lost personally identifiable information (PII) of its’ clients’ patients, including full names, Social Security numbers (SSN), partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information.

This is more than enough information for cybercriminals to launch highly sophisticated phishing and vishing attacks, which can result in disruptive ransomware and millions of dollars in damages. Luckily, there is still no evidence the data leaked on the dark web, or that it was already used by other criminals.

Aesto Health is now offering credit monitoring and identity theft protection services to everyone affected by the breach.

This is now the second-largest healthcare data breach of the year so far, HIPAA Journal confirmed, the largest one being the hit on DentaQuest that exposed 15 million records.

Via HIPAA Journal


Best antivirus software header
The best antivirus for all budgets

Google logo on a black background next to text reading 'Click to follow TechRadar'

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.


Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.