Aesto Health, a healthcare technology company based in Birmingham, Alabama, has suffered a significant data breach affecting over 9.5 million individuals. The breach, which was discovered on December 18, 2025, involved unauthorized access to portions of the company's Amazon Web Services infrastructure. Aesto Health specializes in secure data migration, electronic health record exchanges, and legacy data archiving services for healthcare providers and medical practices.

Upon discovering the unauthorized activity, Aesto Health took immediate action to contain the incident and launched a detailed investigation with the help of cybersecurity experts. The investigation, completed on May 26, 2026, confirmed that personal and health information was exfiltrated by hackers between December 2 and December 18. The stolen data includes names, Social Security numbers, driver's license numbers, other identification numbers, dates of birth, financial account details, medical information, health insurance information, and taxpayer identification numbers.

The company has reported the breach to the US Department of Health and Human Services, which has added Aesto Health to its data breach portal. At least twenty-four Aesto Health clients across several states are affected by the breach, with some choosing to notify potentially impacted individuals directly. The scale and sensitivity of the data involved underscore the critical need for robust security measures in the healthcare industry.