Aesto Health, Everside Health, Together Women’s Health Medical Group and Village Practice Management: More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen

Aesto Health, Everside Health, Together Women’s Health Medical Group and Village Practice Management: More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen

Aesto Health Suffers Major AWS Cyberattack, Exposing 9.5M Patients’ Data

In December 2025, Alabama-based healthcare technology firm Aesto Health fell victim to a cyberattack targeting its Amazon Web Services (AWS) infrastructure, resulting in the exposure of sensitive data belonging to 9.5 million patients. The breach, which occurred between December 2 and December 18, was only reported to the HHS’ Office for Civil Rights in mid-2026, making it the second-largest confirmed healthcare data breach of the year.

The attack compromised personally identifiable information (PII) from over 20 clients, including Village Practice Management, Everside Health, and Together Women’s Health Medical Group. Stolen data included full names, Social Security numbers (SSNs), medical histories, billing details, insurance information, and financial account numbers enough to fuel sophisticated phishing, identity theft, or ransomware attacks.

While no dark web leaks have been confirmed, Aesto Health is providing credit monitoring and identity theft protection to affected individuals. The breach follows the DentaQuest incident, which exposed 15 million records, currently the largest healthcare breach of 2026. The delayed disclosure raises concerns about the timeline of detection and response in critical infrastructure attacks.

Source: https://www.techradar.com/pro/security/more-than-9-5-million-patients-affected-by-aesto-health-breach-names-ssns-financial-details-health-records-and-more-stolen

Aesto Health cybersecurity rating report: https://www.rankiteo.com/company/aesto-health

Everside Health cybersecurity rating report: https://www.rankiteo.com/company/everside-health

VillageMD cybersecurity rating report: https://www.rankiteo.com/company/villagemd

Together Women's Health cybersecurity rating report: https://www.rankiteo.com/company/togetherwomenshealth

"id": "AESEVEVILTOG1788353911",
"linkid": "aesto-health, everside-health, villagemd, togetherwomenshealth",
"type": "Cyber Attack",
"date": "12/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '9.5 million patients',
                        'industry': 'Healthcare',
                        'location': 'Alabama, USA',
                        'name': 'Aesto Health',
                        'type': 'Healthcare Technology Firm'},
                       {'industry': 'Healthcare',
                        'name': 'Village Practice Management',
                        'type': 'Client'},
                       {'industry': 'Healthcare',
                        'name': 'Everside Health',
                        'type': 'Client'},
                       {'industry': 'Healthcare',
                        'name': 'Together Women’s Health Medical Group',
                        'type': 'Client'}],
 'attack_vector': 'AWS infrastructure compromise',
 'customer_advisories': 'Credit monitoring and identity theft protection '
                        'provided to affected individuals',
 'data_breach': {'number_of_records_exposed': '9.5 million',
                 'personally_identifiable_information': ['Full names',
                                                         'Social Security '
                                                         'numbers (SSNs)'],
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Personally Identifiable '
                                              'Information (PII)',
                                              'Medical histories',
                                              'Billing details',
                                              'Insurance information',
                                              'Financial account numbers']},
 'date_detected': '2025-12-18',
 'date_publicly_disclosed': '2026-06-01',
 'description': 'In December 2025, Alabama-based healthcare technology firm '
                'Aesto Health fell victim to a cyberattack targeting its '
                'Amazon Web Services (AWS) infrastructure, resulting in the '
                'exposure of sensitive data belonging to 9.5 million patients. '
                'The breach compromised personally identifiable information '
                '(PII) from over 20 clients, including full names, Social '
                'Security numbers (SSNs), medical histories, billing details, '
                'insurance information, and financial account numbers.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': '9.5 million records',
            'identity_theft_risk': 'High',
            'legal_liabilities': 'Potential',
            'payment_information_risk': 'High',
            'systems_affected': 'AWS infrastructure'},
 'initial_access_broker': {'data_sold_on_dark_web': 'No dark web leaks '
                                                    'confirmed'},
 'references': [{'source': 'HHS’ Office for Civil Rights'}],
 'regulatory_compliance': {'regulations_violated': ['HIPAA'],
                           'regulatory_notifications': 'Reported to HHS’ '
                                                       'Office for Civil '
                                                       'Rights in mid-2026'},
 'response': {'communication_strategy': 'Credit monitoring and identity theft '
                                        'protection provided to affected '
                                        'individuals'},
 'title': 'Aesto Health Suffers Major AWS Cyberattack, Exposing 9.5M Patients’ '
          'Data',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.