US health-IT provider Aesto Health has confirmed a cyberattack affecting more than 9.5 million people. According to the company and the US Department of Health and Human Services (HHS), sensitive patient data was stolen – making it one of the largest healthcare data breaches of 2026.
What happened?
Aesto Health, based in Birmingham, Alabama, provides software that lets hospitals and medical practices migrate, archive and access patient data when replacing electronic health record (EHR) systems. Based on preliminary findings, intruders accessed parts of the company’s Amazon Web Services (AWS) infrastructure between 2 and 18 December 2025 and exfiltrated data. The incident was confirmed after a forensic investigation on 26 May 2026; an initial notice was published in June, and notifications to affected individuals began in August 2026.
Which data is affected?
Aesto Health reported 9,540,683 affected individuals to the HHS Office for Civil Rights (OCR). According to its notice, the following information may have been exposed:
- Names, dates of birth and Social Security numbers
- Driver’s license and taxpayer IDs and other government ID numbers
- Financial account details and health insurance information
- Medical information and health records (PHI)
Around 29 healthcare provider clients are affected. There is no confirmed ransomware element so far, and no threat group has claimed responsibility for the attack.
Context
The case fits a wave of attacks on health-IT and data-migration providers. Because such vendors aggregate data from many clinics, a single intrusion becomes a lever over millions of records. The details remain preliminary, and an OCR investigation is considered likely.
Sources: BleepingComputer, SecurityWeek, The Record, HIPAA Journal.



















