# Massive Data Breach at Aesto Exposes Health Records of 9.5 Million Individuals

*Published September 4, 2026*
*Source: [https://therecord.media/health-data-aesto-cyberattack-leak](https://therecord.media/health-data-aesto-cyberattack-leak)*

## Executive Summary

Aesto has reported a data breach affecting over 9.5 million individuals, compromising sensitive health and personal information. This incident underscores the persistent vulnerability of healthcare data systems to cyberattacks.

## Article

Aesto, a healthcare data company based in Birmingham, Alabama, has disclosed a data breach that compromised sensitive information of over 9.5 million individuals. The breach, which occurred last December, was reported to the Department of Health and Human Services after being initially communicated to customers in June. The attackers accessed Aesto's Amazon Web Services infrastructure between December 2 and December 18, stealing a vast amount of data including names, Social Security numbers, medical records, driver’s license numbers, financial details, and health insurance information. Aesto specializes in data migration and archiving for medical facilities and provides support to healthcare groups undergoing acquisitions. At least 30 healthcare organizations were affected by this breach, with Aesto filing breach notices in multiple states on behalf of its clients, such as Together Women's Health in Texas and California. No group has claimed responsibility for the attack, and Aesto has not commented further on the incident. This breach is part of a troubling trend in the healthcare sector, with companies like Baylor Genetics and CareCloud also reporting significant data breaches this year. Recent weeks have seen similar incidents involving McKesson, Nutex, and Paylogix. Additionally, Park Dental Partners reported a cyberattack to the SEC, highlighting the ongoing threat to healthcare data security.
