A data breach at US healthcare technology provider Aesto Health may have exposed the personal and medical information of 9,540,683 people, according to a filing with the US Department of Health and Human Services (HHS).
Aesto, a private company that operates software used to migrate, archive and retrieve patient records, said the incident involved a limited part of its Amazon Web Services infrastructure. The company’s systems are used by healthcare organisations replacing electronic health record platforms or taking over medical practices.
The unauthorised access took place between 2 and 18 December 2025, but Aesto said it confirmed the breach on 26 May 2026 after an investigation by external forensic specialists and a manual review of documents.
In a notice published on its website on 24 June, the company said protected health information belonging to patients of several healthcare clients “may have been accessed and/or acquired by an unauthorized actor”.
The potentially compromised data included names, dates of birth, medical details and health insurance information. It may also have included driving licence numbers, financial account numbers, individual taxpayer identification numbers, other government identification numbers and Social Security numbers.
The breach is understood to affect patients indirectly through 29 healthcare providers, including VillageMD, Everside Health, Marana Health and Together Women’s Health, according to HIPAA Journal.
Aesto began contacting affected individuals on 21 August. It said those notified could enrol in 24 months of identity theft protection and credit monitoring through Experian.
No threat group had publicly taken responsibility for the attack at the time of reporting. Aesto has not said whether the information was used fraudulently or whether the incident involved the theft of data beyond the information that may have been accessed.
