Hackers stole personal and health information belonging to more than 9.5 million people after breaching healthcare technology company Aesto Health's cloud infrastructure.

 

What happened

Aesto Health, based in Birmingham, Alabama, provides secure data migration, electronic health record (EHR) exchange, and legacy data archiving services to healthcare providers and medical practices. The company discovered unauthorized activity in portions of its Amazon Web Services (AWS) infrastructure on December 18, 2025. Aesto Health contained the incident and launched an investigation with outside cybersecurity experts. On May 26, 2026, an investigation determined that hackers exfiltrated personally identifiable information (PII) and protected health information (PHI) between December 2 and December 18, 2025. The exposed data includes names, Social Security numbers, driver's license numbers, other ID numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers.

 

The backstory

Aesto Health has no prior publicly reported data breaches; the December 2025 AWS incident is the company's first known security event. Other Alabama healthcare organizations, however, have faced breaches recently. Alabama Ophthalmology Associates, a Birmingham eye care practice, reported a January 2025 hack that exposed 131,576 patients' Social Security numbers and health records and later settled a related class action for $850,000. Jackson Hospital in Alabama notified 13,910 patients after its debt collector, Nationwide Recovery Services, was hacked. Huntsville Hospital Health System was separately affected by the 2025 breach at EHR vendor Cerner (Oracle Health).

 

Going deeper

Aesto Health notified the US Department of Health and Human Services (HHS) that 9,540,683 individuals were affected. The HHS added the company to its breach portal on Monday. At least two dozen Aesto Health healthcare provider clients across several states have been affected by the incident, and some of those clients including SpineZone, Everside Health, Aspire Rural Health System, and Greenwood County Hospital have chosen to notify potentially affected patients themselves rather than have Aesto Health do so directly. Some of those client notices show it took roughly five months from detection to confirming which data was involved, and up to eight months before patients were told.

 

Why it matters

This breach did not just expose one organization's patient records, it hit the infrastructure Aesto Health uses to migrate and archive EHR data on behalf of at least two dozen healthcare provider clients. That means a single AWS compromise affected multiple, separate healthcare organizations that trusted Aesto Health to handle their patients' data during migration or archiving. Since some of those provider clients are handling their own patient notifications rather than relying on Aesto Health, affected patients may hear about their exposure from different organizations at different times, which can create confusion about who is actually responsible for the breach and where to turn for help. The gap between detection, confirmation, and patient notification is fairly common, but often comes up in resulting lawsuits, if victims felt that they were harmed by the delay.

 

The bottom line

Healthcare organizations that outsource data migration, EHR exchange, or archiving are only as secure as the vendors handling that data. Aesto Health's breach is a reminder that due diligence on third-party data processors, and clear breach notification agreements with them, matter just as much as an organization's own internal security.

Related: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What's the difference between PII and PHI?

PII is any data that can identify a person, like a name or Social Security number, while PHI is specifically health-related information tied to that person.

 

How does HIPAA apply to vendors like Aesto Health?

Under HIPAA, vendors that handle PHI on behalf of healthcare providers are classified as business associates and must follow the same security and breach notification rules as the providers themselves.

 

How long can healthcare organizations take to report a breach?

Under HIPAA, covered entities generally must notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach, though investigation timelines can extend beyond that before discovery is considered complete.