RSS
TwitterFacebook

Aesto Health Data Breach Affects More Than 9.5 Million Patients Featured

Sensitive medical and personal information, including Social Security numbers, may have been exposed in a major healthcare data breach.

A major data breach involving Aesto Health may have exposed highly sensitive personal and medical information belonging to more than 9.5 million individuals across the United States.

Aesto Health is a Birmingham, Alabama-based healthcare technology company that provides data migration and archival services to hospitals, medical practices, and other healthcare organizations. Patients therefore may have had information maintained by Aesto even if they had never heard of the company or interacted with Aesto directly.

The U.S. Department of Health and Human Services Office for Civil Rights lists the incident as a hacking/IT incident involving a network server and reports 9,540,683 individuals affected. HHS identifies Aesto as a healthcare business associate.

What Happened in the Aesto Health Data Breach?

According to Aesto Health, it detected unauthorized activity affecting a portion of its Amazon Web Services infrastructure on approximately December 18, 2025.

Following a forensic investigation and review of potentially affected files, Aesto determined on May 26, 2026 that an unauthorized actor may have accessed or acquired protected health information stored on its network between approximately December 2 and December 18, 2025. Aesto publicly announced the incident on June 24, 2026 and began notifying affected healthcare clients shortly afterward.

A proposed class action complaint filed September 11, 2026 in the U.S. District Court for the Northern District of Alabama alleges that Aesto failed to adequately protect the personal information entrusted to it and failed to provide affected individuals with timely notification of the breach. Those allegations have not yet been proven in court.

What Information May Have Been Exposed?

The information involved differed from person to person. According to Aesto, potentially affected information included:

  • Full names
  • Dates of birth
  • Social Security numbers
  • Driver’s license numbers
  • Other government identification numbers
  • Individual taxpayer identification numbers
  • Financial account numbers
  • Medical information
  • Health insurance information

Aesto states that Social Security numbers were potentially involved for a limited number of individuals. The complaint similarly describes potentially exposed information as including identifying, financial, insurance and health information.

This combination of medical and identifying information can be particularly concerning because information such as a Social Security number, date of birth or medical history generally cannot simply be replaced like a compromised credit card.

Which Healthcare Providers Were Affected?

Aesto serves healthcare organizations throughout the country. As of September 8, 2026, Aesto’s website identifies 28 healthcare entities connected with the incident, including Women’s Health Associates, Together Women’s Health Medical Group, Marana Health, Nebraska Orthopedic Center, Texas Spine Consultants, Edwards County Medical Center, Catalyst Physician Group and others.

Because Aesto operated behind the scenes as a healthcare data service provider, an individual could potentially receive a breach notification even though the person’s medical treatment was provided by another healthcare organization.

A Class Action Lawsuit Has Been Filed

A class action against Aesto Health was filed on September 11, 2026. The complaint seeks to represent people in the United States whose private information was allegedly accessed during the breach.

The lawsuit asserts claims including negligence, negligence per se, unjust enrichment, breach of fiduciary duty and breach of implied contract. Among other things, plaintiffs contend that affected individuals face risks of identity theft, fraud and misuse of their personal information and may incur time and expense monitoring and protecting their identities.

Aesto, for its part, stated in its breach notice that it had no evidence of identity theft or financial fraud related to the incident at the time of its announcement.

Were You Affected by the Aesto Health Data Breach?

If you received a data breach notification from Aesto Health or one of the healthcare providers affected by the Aesto incident, your personal or medical information may have been involved.

Attorneys are investigating the Aesto Health data breach and potential claims on behalf of affected individuals.

If you received an Aesto Health data breach notice, or believe your information may have been compromised, please complete the confidential form on this page. Providing your information will allow attorneys investigating the incident to determine whether you may have a potential claim.

There is no cost or obligation to submit the form.


Tags:            

Leave a Reply

Your email address will not be published. Required fields are marked *