The Aesto Health breach exposed the data of 9.5 million patients. Here is what happened and what to do
A little-known medical-data vendor, Aesto Health, has disclosed a breach affecting 9,540,683 people, the second-largest confirmed US healthcare breach of 2026 so far by HHS-reported totals. The intrusion happened in December 2025; the public disclosure is what is new now. Here is the timeline, why patients who never heard of Aesto are affected, and the standard steps to take.

Aesto Health, a US company that migrates and archives medical records for healthcare providers, has disclosed a data breach affecting 9,540,683 people, making it, by HHS-reported totals, the second-largest confirmed US healthcare breach of 2026 so far, behind DentaQuest. The important timing point: the intrusion happened in December 2025, and the public disclosure and breach-portal listing in late August and early September 2026 are what is new now. Because Aesto is a behind-the-scenes vendor, many affected people have never heard of it. Exposed data varies by person and can include names, dates of birth, medical and insurance information, and, for a limited number of people, Social Security numbers. No attacker has been named. Aesto says it has no evidence of misuse and is offering free credit monitoring, though the specific offer differs by notice.
Some of the largest health-data breaches involve a company you have never heard of, because so much of healthcare now runs through a small number of specialist vendors. The Aesto Health breach is exactly that kind of incident: nearly 9.5 million people affected through a company most of them never knowingly dealt with. Here is what happened, why it reaches so far, and the standard steps to consider if you may be caught up in it.
What happened, and why it is surfacing only now
The single most important thing to understand is the timeline, because the attack and the disclosure are months apart. Drawing on Aesto's own notice and the reporting of HIPAA Journal and BleepingComputer, the sequence is:
- 2 to 18 December 2025: an unauthorised party accessed part of Aesto's cloud infrastructure.
- 18 December 2025: Aesto identified the incident.
- 26 May 2026: after a forensic investigation and manual document review, Aesto confirmed the scope and who was affected.
- 26 June 2026: Aesto first notified its healthcare-provider clients.
- Around 21 to 25 August 2026: individual notification letters began going out to affected people.
- Late August 2026: the breach appeared on the US Department of Health and Human Services (HHS) Office for Civil Rights public breach portal, logged at 9,540,683 people.
- 1 September 2026: the breach was widely reported.
So the intrusion is roughly nine months old. What is new now is the public disclosure and the portal listing, not the attack itself. That gap, common in large breaches, is itself part of the story.
Why you might be affected by a company you never used
Aesto Health (legally Aesto, LLC) is a healthcare-technology company based in Birmingham, Alabama, that provides data migration, electronic health record exchange and legacy data archiving services for medical providers. In plain terms, when a clinic or health system switches or retires its electronic health record system, or is acquired, it often hands historical patient records to a vendor like Aesto to migrate or store. That makes Aesto a business associate under US health-privacy law, a behind-the-scenes processor rather than a clinic you visit.
That is why people who have never heard of Aesto are affected: their provider gave Aesto their records to archive, and those records were being held by Aesto when its cloud environment was breached. According to HIPAA Journal, roughly 30 provider organisations are implicated, with publicly named examples including VillageMD, Everside Health, Marana Health and Together Women's Health; SpineZone confirmed its own involvement in a separate state breach filing. So the letter, if you get one, comes from a company you never chose, about care you received somewhere else. It is the same concentration risk we saw in Poland's MyDr vendor breach: one supplier becomes a single point of failure for millions of patients across many clinics.
What data was exposed
Here precision matters, and the answer is that it varies by individual. Across all affected people, the categories Aesto lists in its substitute notice include full names, dates of birth, medical information, driver's licence numbers, financial account numbers, health-insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers.
Two caveats are important and easy to lose. First, per CyberInsider, Social Security numbers were involved for only a limited number of people, not all 9.5 million. Second, the exact mix differs by person and by provider: one provider's notification, for example, stated the affected data did not include patients' medical condition, treatment or history. So "medical records were exposed" is true in aggregate but not universal. The accurate way to read it is that, depending on the individual, exposed information may have included some of those categories, and the letter you receive should specify which apply to you.
Aesto's response and the "no evidence of misuse" claim
Aesto says it engaged outside forensic experts, has implemented additional safeguards, and set up a dedicated toll-free line (833-918-8060). It also states it has "no evidence of any identity theft or financial fraud related to this incident."
That statement should be read as Aesto's position, not an independent finding. Absence of evidence of misuse is not the same as evidence that data will not be misused, particularly with information like Social Security numbers that can surface long after a breach. It is reasonable to note Aesto's reassurance and still take protective steps.
The free monitoring offer varies, so read your letter
Aesto is offering complimentary credit monitoring and identity-protection services, but the specific offer is not uniform across notices, so this is a case where the details in your own letter govern. Reporting and the notices seen so far show at least two versions: some individuals were offered 12 months of monitoring through TransUnion (via Cyberscout), with enrolment within 90 days of the letter's date, while others were offered 24 months through Experian, with enrolment reported by 30 November 2026. The takeaway is practical: do not assume a single flat offer, and follow the specific enrolment code and deadline printed in the letter you receive.
Where this ranks
By the number of individuals reported to HHS in 2026, this is the second-largest confirmed US healthcare breach of the year so far, behind DentaQuest, which reported about 15 million. That ranking is a point-in-time figure: it is based on breaches reported to HHS this year to date and can change as more incidents are disclosed or as figures are revised. It is a useful sense of scale, not a permanent standing.
No attacker has been named
As of early September 2026, no threat actor or ransomware group has claimed the Aesto breach, and Aesto has not publicly named one. The notices do not indicate whether ransomware was involved. It is worth stating plainly because breach coverage often attaches a well-known group to an incident by association. In this case there is no confirmed attribution, and the actor behind the much larger DentaQuest breach should not be assumed to be connected here.
What to do if you may be affected
The following are the standard steps recommended by the US Federal Trade Commission and set out in breach notices generally, offered as general information rather than advice tailored to any individual:
- Watch for a mailed notice from Aesto, LLC (handled via Cyberscout), and check the HHS breach portal. If unsure, Aesto's line is 833-918-8060.
- Enrol in the offered monitoring using the specific code, provider and deadline in your letter, since the offer varies.
- Request your free credit reports (in the US, at annualcreditreport.com) and review them.
- Consider a fraud alert or a credit freeze. A credit freeze, which is free to place and lift at each of the three major bureaus, is one of the strongest protective measures in standard FTC guidance.
- Watch for medical-identity misuse: review the Explanation of Benefits from your insurer and provider bills for care you did not receive.
- Use official resources: the FTC's IdentityTheft.gov is the standard place to report suspected identity theft and get a recovery plan.
The same proactive-monitoring mindset applies whenever sensitive records leak, even if the specific steps differ by breach type, from health data to the wallet and account breaches we have covered in crypto. For more, see our full privacy coverage.
Frequently asked questions
How many people were affected by the Aesto Health breach?
Aesto reported 9,540,683 affected individuals, the figure logged on the HHS breach portal. That makes it the second-largest confirmed US healthcare breach of 2026 so far, behind DentaQuest (about 15 million), by the count of individuals reported to HHS this year to date.
When did the breach happen, and why am I only hearing about it now?
The unauthorised access happened between 2 and 18 December 2025 and was identified on 18 December 2025. Aesto confirmed the scope in May 2026, notified providers in June, sent individual letters in late August, and the breach appeared on the HHS Office for Civil Rights portal in late August 2026, drawing wide coverage on 1 September. The attack is months old; the public disclosure is what is new.
Why am I affected if I have never heard of Aesto?
Aesto is a business associate that migrates and archives medical records for healthcare providers. If a clinic or health system you used handed your records to Aesto to store or migrate, your data could be involved even though you never dealt with Aesto directly. Around 30 provider organisations are implicated.
What information was exposed?
It varies by person. Across all those affected, categories include names, dates of birth, medical information, driver's licence numbers, financial account numbers, health-insurance information, taxpayer identification numbers, other government IDs and Social Security numbers. Social Security numbers were involved for only a limited number of people, and some notices excluded medical history. Your letter should specify what applies to you.
Who was behind the attack?
As of early September 2026, no threat actor or ransomware group had claimed responsibility, and Aesto had not named one. The notices do not confirm whether ransomware was used.
What should I do if I think I am affected?
Standard FTC-recommended steps include watching for a notice from Aesto, enrolling in the offered monitoring using the code and deadline in your letter (the offer varies), checking your credit reports, considering a credit freeze, watching for medical-identity misuse on your Explanation of Benefits, and reporting any suspected identity theft at IdentityTheft.gov. This is general information, not advice for any individual situation.


