Aesto Health Discloses Major Data Breach Impacting Healthcare Patient Records
Aesto Health, a Birmingham, Alabama-based healthcare data management company, recently disclosed a data breach that occurred in December 2025, potentially exposing sensitive patient information. As a third-party vendor handling data for healthcare providers, the breach may have affected patients across multiple organizations.
The incident, detected on or around December 18, 2025, involved unauthorized access to a portion of Aesto Health’s Amazon Web Services (AWS) infrastructure. Following an investigation with external cybersecurity experts, the company confirmed on May 26, 2026, that protected health information (PHI) and personally identifiable information (PII) were accessed or acquired between December 2 and December 18, 2025.
Exposed data includes full names, Social Security numbers, driver’s license numbers, dates of birth, medical histories, health insurance details, and billing information. While Aesto Health stated it has no evidence of misuse, the breach was reported to the California and Vermont attorneys general on July 31, 2026, with 91 Vermont residents identified as affected.
Aesto Health notified impacted healthcare providers on June 26, 2026, and began sending written notices to affected individuals. As part of its response, the company is offering complimentary identity protection services, including credit monitoring, dark web surveillance, and identity restoration assistance through Privacy Solutions ID by Epiq.
The company has also established a dedicated response line (833-918-8060) and a mailing address for affected individuals seeking further information. Despite the breach, Aesto Health emphasized its commitment to enhancing security measures to prevent future incidents.
Source: https://www.claimdepot.com/data-breach/aesto-health-2026
Aesto Health cybersecurity rating report: https://www.rankiteo.com/company/aesto-health
"id": "AES1785652646",
"linkid": "aesto-health",
"type": "Breach",
"date": "12/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Patients across multiple '
'healthcare providers',
'industry': 'Healthcare',
'location': 'Birmingham, Alabama, USA',
'name': 'Aesto Health',
'type': 'Healthcare Data Management Company'}],
'attack_vector': 'Unauthorized access to AWS infrastructure',
'customer_advisories': 'Sent written notices to affected individuals; offered '
'complimentary identity protection services (credit '
'monitoring, dark web surveillance, identity '
'restoration assistance)',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Full names',
'Social Security numbers',
'Driver’s license numbers',
'Dates of birth',
'Medical histories',
'Health insurance details',
'Billing information']},
'date_detected': '2025-12-18',
'date_publicly_disclosed': '2026-05-26',
'description': 'Aesto Health, a Birmingham, Alabama-based healthcare data '
'management company, disclosed a data breach that occurred in '
'December 2025, potentially exposing sensitive patient '
'information. The breach may have affected patients across '
"multiple healthcare providers due to Aesto Health's role as a "
'third-party vendor.',
'impact': {'data_compromised': 'Protected health information (PHI) and '
'personally identifiable information (PII)',
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': 'Amazon Web Services (AWS) infrastructure'},
'investigation_status': 'Completed',
'post_incident_analysis': {'corrective_actions': 'Enhanced security measures '
'to prevent future '
'incidents'},
'references': [{'source': 'Aesto Health Disclosure'}],
'regulatory_compliance': {'regulatory_notifications': ['Reported to '
'California and '
'Vermont attorneys '
'general on July 31, '
'2026']},
'response': {'communication_strategy': 'Notified impacted healthcare '
'providers on June 26, 2026; sent '
'written notices to affected '
'individuals; established a dedicated '
'response line and mailing address',
'remediation_measures': 'Enhanced security measures to prevent '
'future incidents',
'third_party_assistance': 'External cybersecurity experts'},
'stakeholder_advisories': 'Notified impacted healthcare providers on June 26, '
'2026',
'title': 'Aesto Health Data Breach Impacting Healthcare Patient Records',
'type': 'Data Breach'}