
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affected more than 9.5 million people.
The privately held technology company provides software-as-a-service solutions that help healthcare organizations migrate, archive and access patient data when replacing electronic health record systems or acquiring medical practices.
The company first informed the public about the attack on June 24 through a notice on its website, saying that a “limited portion” of its Amazon Web Services infrastructure had been compromised.
However, the breach took place in December 2025 and was confirmed internally on May 26 following a forensic investigation by external experts.
“Following a thorough forensic investigation and manual document review, we confirmed on May 26, 2026 that between or about December 2, 2025 and December 18, 2025, certain protected health information belonging to patients of various customers of Covered Entities stored on the Aesto network may have been accessed and/or acquired by an unauthorized actor.” the statement reads.
In a report to the US Department of Health and Human Services, Aesto Health said the data breach affected 9,540,683 individuals.
“The information included full names, dates of birth, medical information, driver’s license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and social security numbers.”
The HIPAA Journal says that the incident indirectly affected 29 health care providers, including VillageMD, Everside Health (Marathon Health), Marana Health and Together Women’s Health.
On August 21, the company began notifying affected individuals of the data breach, providing details of the incident and instructions on how to enroll in a 24-month identity theft protection and credit monitoring service through Experian.
The Aesto Health data breach follows a string of similar incidents at other health technology software companies, including iRhythm, Xolis, Medronic, MCBS, Unlimited Technology Systems, CareCloud, Nutex Health and McKesson.
At the time of writing, no threat group has publicly announced the attack on Aesto Health.
Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.
The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.
