Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

Aesto Health Data Breach Affects 9.54 Million Individuals

Aesto LLC, operating as Aesto Health, says a data breach affected 9,540,683 individuals.

The company provides software-as-a-service tools that help healthcare organizations migrate, archive, and access patient data when replacing electronic health record systems or acquiring medical practices.

Aesto Health said a limited portion of its Amazon Web Services infrastructure was compromised. The intrusion occurred between December 2 and December 18, 2025, and was confirmed internally on May 26, 2026, after an external forensic investigation and manual document review.

The company said protected health information belonging to patients of various Covered Entity clients may have been accessed or acquired by an unauthorized actor. The exposed information included full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers.

According to HIPAA Journal, the incident indirectly affects 29 healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women’s Health.

Aesto Health began notifying affected individuals on August 21 and offered a 24-month identity theft protection and credit monitoring service through Experian. No threat group had publicly claimed responsibility at the time of writing.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.