More than 9.5 million patient records affected by Aesto Health data breach: what you need to know

Screen graphic showing data breach warning
(Image credit: Getty Images)

Aesto Health recently disclosed a data breach affecting more than 9.5 million people. Aesto is a software company for healthcare organizations that produces solutions to help them organize patient data when replacing health records systems.

Spotted by Bleeping Computer, the company first posted a notice of the attack on June 24 via its website. However, the actual incursion took place over two weeks in December of 2025. It apparently wasn't discovered until May 26 of this year.

"After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor," the notice reads.

Latest Videos FromTom's Guide

Apparently, the breach involved unauthorized access via Aesto's Amazon Web Services infrastructure.

What was taken

Hacker using a stolen social security card

(Image credit: Blazej Lyjak/Shutterstock)

In its report, Aesto Health confirmed that the breach affects 9,540,683 people. Unfortunately, that data included full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer ID numbers, Social Security numbers and other government identification numbers.

According to the HIPAA Journal, the breach spans 29 different organizations including Edwards County Medical Center, Marana Health, My Doctor, LLC, the Nebraska Orthopedic Center and Women's Health Associates.

The company started informing impacted individuals of the breach on August 21, providing details about the incident and providing identity theft protection and credit monitoring via Experian.

As noted by Bleeping Computer, this incident follows an unfortunate series of breaches that have affected health care companies including CareCloud, Nutex Health, iRhythm and McKesson. The breaches have ranged in size from a couple of hundred thousand to millions of records.

Per Aesto Health and our own review, no threat groups have publicly claimed the attack, unlike other recent ones claimed by the hacker group ShinyHunters.

How to stay safe after a data breach

An open lock depicting a data breach

(Image credit: Shutterstock)

Check out the full list of companies from the HIPAA Journal, and if you've used any health care organization, you might receive a data breach notification letter from Aesto. If you do, take advantage of the Experian coverage. Keep an eye on your mailbox since notification letters arrive the old-fashioned way.

Even if Aesto doesn't send you a notification letter, you may want to take advantage of one of the best identity theft protection services to protect your identity.

While no one has claimed the attachment, a bad actor could use your information to launch targeted phishing attacks. Phishing emails could contain malicious links or even malware.

Health companies appear especially vulnerable as the summer comes to a close, and every company should be taking this threat seriously. Hopefully, companies are bolstering their cybersecurity right now.


Google News

Follow Tom's Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds.


More from Tom's Guide

Scott Younker
West Coast Reporter

Scott Younker is the West Coast Reporter at Tom’s Guide. He covers all the lastest tech news. He’s been involved in tech since 2011 at various outlets and is on an ongoing hunt to build the easiest to use home media system. When not writing about the latest devices, you are more than welcome to discuss board games or disc golf with him. He also handles all the Connections coverage on Tom's Guide and has been playing the addictive NYT game since it released.
Something to share? Send secure tips on Signal: scyo1.55.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.