A severe security breach at Aesto Health has exposed the personal and medical records of over 9.5 million people via a compromise of their AWS infrastructure.

  • Over 9.5 million individuals had PII and PHI exfiltrated.
  • The breach occurred within the company's Amazon Web Services (AWS) infrastructure.
  • Compromised data includes SSNs, financial accounts, and medical histories.

In a staggering blow to healthcare data privacy, Aesto Health, a Birmingham, Alabama-based healthcare technology firm, has confirmed a massive data breach affecting 9,540,683 individuals. The company, which specializes in secure data migration and electronic health record (EHR) exchanges, became the victim of a sophisticated cyberattack targeting its cloud environment.

The breach was first detected on December 18, 2025. According to a formal incident notice issued in June 2026, unauthorized actors gained access to portions of Aesto Health's Amazon Web Services (AWS) infrastructure between December 2 and December 18, 2025.

Why This Matters

BozokMedia analysis shows that this breach is particularly perilous because it combines Personally Identifiable Information (PII) with Protected Health Information (PHI). This combination is a goldmine for cybercriminals, enabling them to conduct highly targeted phishing attacks or commit comprehensive medical identity theft, where attackers use a victim's identity to obtain expensive medical procedures.

The intersection of cloud misconfiguration and sensitive health data creates a systemic risk that can haunt victims for a lifetime.

The scope of the stolen data is alarmingly broad. The exfiltrated information includes full names, Social Security numbers, driver’s license numbers, dates of birth, financial account numbers, detailed medical information, health insurance details, and taxpayer identification numbers.

Aesto Health has officially notified the US Department of Health and Human Services (HHS). Consequently, the company has been added to the HHS data breach portal. The ripple effect of this breach extends to at least two dozen healthcare provider clients across multiple US states, some of whom are now independently notifying their patients.

Data CategoryRisk LevelPotential Impact
Personal Identifiers (PII)HighIdentity Theft / Fraud
Health Records (PHI)CriticalMedical Fraud / Privacy Loss
Financial DataHighMonetary Loss / Account Takeover

Historically, the healthcare sector has remained a top target for ransomware and data exfiltration groups due to the high value of medical records on the dark web. This incident underscores the vulnerability of legacy data archiving services when transitioned to cloud environments without rigorous, continuous security auditing.

Did You Know?: Medical records are often sold for 10 to 50 times more than credit card numbers on the dark web because they contain permanent data that cannot be changed.

Frequently Asked Questions

Q1: What specific information was leaked in the Aesto Health breach?
A: The leak included names, SSNs, driver's licenses, financial account numbers, and protected health information (PHI).

Q2: How did the hackers gain access?
A: The attackers exploited vulnerabilities within portions of the company's Amazon Web Services (AWS) infrastructure.