9.5 Million People's Health and Personal Records Stolen in Aesto Health Breach

A Birmingham, Alabama healthcare data company discovered in December 2025 that criminals had broken into its cloud storage and stolen records including Social Security numbers, medical histories, and financial account details belonging to more than 9.5 million people.

ThreatVectr Newsdesk· 3 min read
Photoreal editorial image, full-frame 16:9, of a dimly lit hospital corporate office at night with rows of empty desks, a single monitor glowing with abstract c
Share

Key points

  • Aesto Health, a healthcare data services company based in Birmingham, Alabama, confirmed a breach affecting 9,540,683 people.
  • Criminals accessed its Amazon Web Services cloud storage between December 2 and 18, 2025, but the breach was not fully investigated until May 26, 2026.
  • Stolen data includes Social Security numbers, driver's licence numbers, medical records, health insurance details, and financial account numbers.
  • At least two dozen healthcare providers who used Aesto Health's services are caught up in the incident across multiple US states.
  • Aesto Health has reported the breach to the US Department of Health and Human Services, which added the company to its public breach register on Monday.

Aesto Health is not a name most patients would recognise. The company works in the background, helping hospitals and medical practices move patient records between systems, store old files, and exchange electronic health records safely. That background role is precisely what made the breach so wide-reaching: one company held data belonging to clients across many states.

What happened, and when?

Criminals broke into portions of Aesto Health's Amazon Web Services infrastructure, the cloud computing platform the company used to store client data, and spent roughly two weeks pulling out files before anyone noticed. The intrusion ran from December 2 to December 18, 2025, when Aesto Health detected the unauthorised activity and shut it down.

Investigators, including external cybersecurity specialists the company brought in, then spent months working out exactly what had been taken. That review concluded on May 26, 2026, and the company issued its breach notice in June 2026.

The gap between discovery and public notification, roughly six months, is long by any measure, though federal rules allow time for investigation before disclosure.

What was stolen?

The list is extensive. Names, Social Security numbers, driver's licence numbers, dates of birth, taxpayer identification numbers, financial account numbers, medical information, and health insurance details were all among the records stolen. In short: almost everything a criminal needs to open a fraudulent account, file a false tax return, or sell an identity.

At least 24 healthcare providers who relied on Aesto Health's services have been pulled into the incident. Some have chosen to contact affected patients directly themselves.

Should affected people be worried?

Yes, practically speaking. Social Security numbers and medical records together are among the most valuable combinations a criminal can hold. They can be sold, used to open credit accounts, or used to fraudulently bill insurers.

Data type stolen Risk to individuals
Social Security number Identity theft, fraudulent credit applications
Financial account numbers Unauthorised bank or card transactions
Medical and insurance records Insurance fraud, medical identity theft
Driver's licence number Identity fraud, false account openings
Taxpayer ID number Fraudulent tax filings

If you received a notification letter from Aesto Health or any of its healthcare provider clients, accept any free credit monitoring offer included. Place a fraud alert, or a full credit freeze, with the major credit bureaus. Watch explanation-of-benefits statements from your health insurer for treatments you never received. Report anything suspicious to the US Federal Trade Commission at reportfraud.ftc.gov.

© 2026 Threat Vectr