A Vendor You May Never Have Heard Of Just Reported 9.5 Million Patients Breached

Aesto Health reported a breach affecting 9.5 million patients to HHS — check whether your organization uses it.

Get Advisory Support
High

Aesto LLC, which operates as Aesto Health, has reported to the U.S. Department of Health and Human Services that a data breach affects 9,540,683 individuals. The company is not a hospital or a health plan. It sells software-as-a-service used by healthcare organizations to migrate, archive, and access patient data when they replace an electronic health record system or acquire a medical practice — which is to say, it holds the records that other organizations moved off their own systems. The timeline is the part worth reading twice. Aesto says the unauthorized access occurred between on or about December 2 and December 18, 2025, that it confirmed the exposure internally on May 26, 2026 after a forensic investigation by outside specialists, that it posted a public notice on its website on June 24 describing a compromise of a limited portion of its Amazon Web Services infrastructure, and that it began notifying affected individuals on August 21. The figure of 9,540,683 individuals was reported to HHS. According to the company, the information involved includes full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. The HIPAA Journal reports that the incident indirectly affects 29 healthcare providers, among them VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women's Health. Aesto is offering 24 months of identity theft protection and credit monitoring through Experian. No threat group has publicly claimed the attack.

Recommended action: Start with a question most organizations cannot answer quickly: who is holding our old patient records right now? When a practice replaces an electronic health record, or a group acquires a clinic, the legacy data rarely disappears. It gets migrated to an archive platform and then sits there for years, quietly, under a contract someone signed during a system conversion. Those vendors are business associates, they hold complete historical records rather than active ones, and they are almost never included in the annual vendor review because no one uses them day to day. Build the list this month: every archive, migration, conversion, and legacy read-only platform your organization or any practice you acquired has ever used, who holds it now, what is in it, and whether a current business associate agreement is on file. Then look at the notification timeline in this case, because it is the second lesson. Unauthorized access in December 2025, internal confirmation in May 2026, individual notices beginning in August 2026. Under 45 CFR §164.410 a business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days from discovery, and your own clock to notify individuals under 45 CFR §164.404 runs from your discovery. Pull your agreements and check whether they state a specific number of days for the vendor to tell you, whether they require notice of suspected as well as confirmed incidents, and whether they obligate the vendor to cooperate with your own investigation. If your template is silent, fix the template before the next renewal. Finally, consider retention. The strongest control over a legacy archive is not having one: if the retention period for a set of records has passed and there is no legal hold, ask whether the archive can be reduced or the contract terminated with certified destruction. And note the data elements here — Social Security numbers, driver's license numbers, and financial account numbers — which carry identity theft exposure and can trigger notification duties beyond HIPAA depending on where the affected individuals live.
Sources: Aesto Health notice of data security incident, U.S. Department of Health and Human Services breach report, The HIPAA Journal, BleepingComputer (September 1, 2026).

← All security bulletins

Bulletins summarize publicly reported information for awareness and are not a substitute for vendor advisories or a tailored assessment.

Worried about a bulletin above?

We can assess your exposure to the threats above and other active campaigns, and help you remediate quickly.

Request an Exposure Check