Aesto Health, a Birmingham, Alabama company that migrates and archives electronic health records for medical practices, has confirmed that a December 2025 intrusion into its Amazon Web Services environment exposed data on 9,540,683 people. The figure, reported to the HHS Office for Civil Rights, makes this the second largest healthcare breach confirmed in 2026.
Attackers were inside a portion of the AWS infrastructure from December 2 to December 18, 2025, when Aesto detected the activity and says it contained the incident. The investigation did not confirm the full scope until May 26, 2026. Provider clients were notified in late June, and letters to individuals started going out on August 21, 2026. That is more than eight months from detection to individual notice.
The stolen data includes names, Social Security numbers, driver's license and state ID numbers, financial account numbers, taxpayer identification numbers, dates of birth, medical histories, health insurance details, and claims information. More than two dozen provider organizations across several states are affected through Aesto, including VillageMD, Everside Health, Marana Health, and Together Women's Health. Some clients sent their own notifications rather than waiting.
No ransomware or extortion group has claimed the attack, and Aesto has not said how the attackers got into the AWS environment. Affected individuals are being offered 24 months of identity theft protection and credit monitoring through Experian.
The exposure for manufacturers sits in the business model. Legacy patient data concentrates in whichever vendor holds the archiving contract, and it stays there long after the system that produced it is retired. A due diligence review that stops at the EHR vendor misses where the records actually live.