Aesto Health Data Breach Exposes Sensitive Patient Information
Aesto Health, a Birmingham, Alabama-based healthcare IT services provider, confirmed a significant data breach affecting tens of millions of healthcare records. The company, which specializes in HIPAA-compliant data management for healthcare organizations, detected unauthorized access to its Amazon Web Services (AWS) infrastructure between November 5 and December 6, 2023, with the breach officially discovered on May 14, 2024.
The incident exposed a wide range of sensitive data, including health records, Social Security numbers, claims and billing information, driver’s license numbers, full names, dates of birth, health insurance policy numbers, medical histories, and state identification numbers. Aesto Health serves tens of thousands of healthcare professionals, meaning the breach could impact a large number of patients and providers.
Following a forensic investigation and manual document review, the company confirmed the extent of the exposure. Legal firm Shamis & Gentile P.A., which specializes in data breach class actions, is now investigating potential compensation claims for affected individuals, citing damages such as lost time, financial losses, and emotional distress. The breach underscores ongoing risks in healthcare data security, particularly for third-party SaaS platforms handling sensitive patient information.
Source: https://www.claimdepot.com/investigations/aesto-health-data-breach-2026
Aesto Health TPRM report: https://www.rankiteo.com/company/aesto-health
"id": "aes1785652687",
"linkid": "aesto-health",
"type": "Breach",
"date": "11/2023",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Tens of thousands of healthcare '
'professionals and their '
'patients',
'industry': 'Healthcare',
'location': 'Birmingham, Alabama',
'name': 'Aesto Health',
'type': 'Healthcare IT Services Provider'}],
'attack_vector': 'Unauthorized access to AWS infrastructure',
'data_breach': {'number_of_records_exposed': 'Tens of millions',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Health records',
'Social Security numbers',
'Claims and billing information',
'Driver’s license numbers',
'Full names',
'Dates of birth',
'Health insurance policy numbers',
'Medical histories',
'State identification numbers']},
'date_detected': '2024-05-14',
'description': 'Aesto Health, a Birmingham, Alabama-based healthcare IT '
'services provider, confirmed a significant data breach '
'affecting tens of millions of healthcare records. The company '
'detected unauthorized access to its Amazon Web Services (AWS) '
'infrastructure, exposing sensitive data including health '
'records, Social Security numbers, claims and billing '
'information, and other personally identifiable information.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'sensitive data exposure',
'data_compromised': 'Tens of millions of healthcare records',
'identity_theft_risk': 'High',
'legal_liabilities': 'Potential class action lawsuits',
'systems_affected': 'AWS infrastructure'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Ongoing risks in healthcare data security, particularly '
'for third-party SaaS platforms handling sensitive patient '
'information',
'references': [{'source': 'Cyber incident description'}],
'regulatory_compliance': {'legal_actions': 'Class action investigation by '
'Shamis & Gentile P.A.',
'regulations_violated': 'Potential HIPAA '
'violations'},
'response': {'third_party_assistance': 'Forensic investigation and manual '
'document review'},
'title': 'Aesto Health Data Breach Exposes Sensitive Patient Information',
'type': 'Data Breach'}