type: incident ยท created: 2026-09-02 ยท updated: 2026-09-02 ยท tags: [incident, data-breach, healthcare, business-associate, confirmed-breach] ยท confidence: high ยท severity: critical ยท affected_sectors: [healthcare] ยท au_impact: false
Aesto Health Discloses Breach Affecting 9.5 Million Patients
Summary
Aesto Health, a healthcare software-as-a-service provider that helps organisations migrate, archive and access patient data during electronic-health-record transitions, disclosed a breach affecting more than 9.5 million people.
Key Facts
- Timeframe: Breach occurred between ~2 and 18 December 2025; confirmed on 26 May following an external forensic investigation.
- Scale: Affects 9,540,683 individuals (confirmed via report to the US Department of Health and Human Services).
- Data exposed: Full names, dates of birth, medical information, driver's licence numbers, financial account numbers, health insurance data, taxpayer identification numbers and Social Security numbers.
- Indirect impact: Incident indirectly impacts 29 healthcare providers, including VillageMD, Everside Health, Marana Health and Together Women's Health.
- Notification: Began 21 August.
- Attribution: No group has publicly claimed the attack.