A massive data breach at Aesto Health has exposed the sensitive medical and personal information of over 9.5 million individuals. The breach includes Social Security numbers and financial details.

  • Over 9.5 million individuals affected by the breach.
  • Compromised data includes names, DOB, medical history, and Social Security numbers.
  • The intrusion occurred in December 2025 but was confirmed in May 2026.
  • Affected users are being offered 24 months of identity theft protection via Experian.

A massive cybersecurity crisis has unfolded in the healthcare technology sector. Aesto LLC, operating as Aesto Health, has disclosed a catastrophic data breach affecting 9,540,683 individuals. The company, which provides critical software-as-a-service (SaaS) solutions for healthcare data migration and archiving, confirmed that a portion of its Amazon Web Services (AWS) infrastructure was compromised.

The breach was not a recent event; forensic investigations revealed that the unauthorized access occurred between December 2 and December 18, 2025. However, the intrusion was only confirmed internally on May 26, 2026, following an extensive review by external specialists.

Scope of the Data Theft

The scale of the information stolen is deeply concerning for patient privacy. According to reports to the U.S. Department of Health and Human Services, the stolen data includes: full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance details, and Social Security numbers.

When attackers bypass perimeter defenses using valid credentials, standard prevention tools often fail to detect the movement, leaving sensitive data vulnerable.

Why This Matters

BozokMedia analysis shows that this incident highlights a systemic vulnerability in the healthtech supply chain. The breach indirectly impacts 29 healthcare providers, including major names like VillageMD, Everside Health, and Together Women’s Health. This incident is part of a worrying trend where healthtech software companies—such as McKesson, CareCloud, and iRhythm—have all faced similar breaches recently.

The vulnerability is exacerbated by the fact that once attackers obtain valid credentials, the effectiveness of most prevention technologies drops significantly, often blocking only 37% of subsequent actions.

Historical Context of Healthtech Breaches

The healthcare industry has become a prime target for cybercriminals due to the high value of medical records. The Aesto Health breach follows a string of high-profile incidents at firms like Nutex Health and Novocure, signaling a coordinated or at least highly persistent threat landscape targeting medical data infrastructure.

Did You Know?: Medical records are significantly more valuable on the dark web than credit card numbers because they contain permanent information that cannot be easily changed.

Frequently Asked Questions

1. How can I know if I am affected?
Aesto Health has begun notifying impacted individuals directly since August 21, 2026.

2. What steps should I take to protect myself?
Affected individuals should enroll in the 24-month identity theft protection and credit monitoring service provided through Experian.