More than 9.5 million people had their personal and health information stolen in a data breach at healthcare technology company Aesto Health.
Based in Birmingham, Alabama, Aesto Health offers secure data migration, electronic health record (EHR) exchanges, and legacy data archiving services to healthcare providers and medical practices.
The data breach, the company said in a June 2026 incident notice, was discovered on December 18, 2025, and involved portions of its Amazon Web Services (AWS) infrastructure.
“Upon detecting the unauthorized activity, we immediately contained the incident and commenced a thorough investigation. As part of our investigation, we engaged leading cybersecurity experts to identify what personal information, if any, was involved,” Aesto Health said.
On May 26, 2026, the company’s investigation determined that hackers exfiltrated personally identifiable information (PII) and protected health information (PHI) between December 2 and 18.
The compromised information includes names, Social Security numbers, driver’s license numbers, other ID numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers.
Aesto Health has notified the US Department of Health and Human Services (HHS) that 9,540,683 individuals are impacted by the data breach. HHS added the company to its data breach portal on Monday.
At least two dozen Aesto Health healthcare provider clients across several states have been affected by the incident, some of which have chosen to notify the potentially affected people themselves.
Related: McKesson Confirms Data Breach as Attacker Deadline Looms
Related: Extortion Group Claims Manchester Airports Group Data Breach
Related: Personal Information Exposed in Apollo Global Data Breach
Related: CareCloud Data Breach Impact Grows to 3.7 Million Individuals


