CybersecuritySeptember 1, 2026· via Security Affairs

Healthcare giant Aesto Health hit by AWS breach, 9.5 million records exposed

Healthcare giant Aesto Health hit by AWS breach, 9.5 million records exposed

Image : Security Affairs

Aesto Health, a U.S. healthcare technology provider, has disclosed a data breach affecting more than 9.5 million individuals after attackers gained access to part of its Amazon Web Services infrastructure. The company detected the incident on December 18, 2025, but forensic analysis later revealed unauthorized access between December 2 and 18, 2025. While Aesto states it found no evidence of identity theft or financial fraud tied to the breach, the exposed data includes names, birth dates, medical records, insurance details, and, for some individuals, sensitive identifiers like Social Security numbers.

Behind the breach: cloud missteps and healthcare stakes

Aesto Health specializes in managing and protecting electronic health records (EHR), data migration, and long-term archiving for healthcare providers. The breach underscores the vulnerabilities that can emerge when legacy medical data and modern cloud infrastructure intersect. By compromising AWS storage, attackers bypassed perimeter defenses and accessed protected health information (PHI) stored within the company’s network. The incident also reveals a lag between detection and confirmation: Aesto only verified the breach’s scope on May 26, 2026, nearly five months after the initial intrusion.

What’s next for patients and providers

Starting June 26, 2026, Aesto began notifying affected healthcare clients whose patients’ data may have been accessed. The company has pledged to bolster security and set up a dedicated helpline for inquiries. It also reported the breach to the U.S. Department of Health and Human Services (HHS), which logged the incident as impacting 9,540,683 individuals. While no immediate financial or identity fraud has been reported, the long-term risk remains, particularly for those whose Social Security numbers were exposed.

Why it matters

This breach highlights the persistent tension between healthcare’s need for interoperable data and cloud security realities. For patients, the exposure of PHI and sensitive identifiers raises concerns about future misuse, even if fraud hasn’t occurred yet. For healthcare providers relying on third-party vendors like Aesto, it’s a reminder to scrutinize cloud security practices and incident response timelines. For the industry, the case adds to growing calls for stronger enforcement of HIPAA and cloud-specific safeguards, especially as more medical data migrates to shared infrastructures.


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home