Aesto Health Discloses Breach Impacting ~10M After Months-Long Investigation

Aesto Health disclosed a massive healthcare data breach affecting more than 9.5 million people, after hackers stole personal and protected health information from portions of the company’s AWS infrastructure. The Birmingham-based healthcare technology company provides secure data migration, EHR exchanges, and legacy data archiving services to healthcare providers and medical practices. Aesto discovered the incident on December 18, 2025, and later determined that attackers exfiltrated data between December 2 and December 18, including names, Social Security numbers, driver’s license numbers, other ID numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers.

The scale is especially serious because Aesto sits inside the healthcare data supply chain. A breach at one healthcare technology vendor can impact dozens of provider clients across multiple states, exposing patient data even when the affected individuals may never have heard of the vendor. The timeline also matters: the incident was discovered in December, but the investigation did not determine the affected information until May 26, 2026. For healthcare providers, patients, regulators, and legal teams, that months-long gap creates uncertainty about who was affected, which clients were impacted, what PHI was copied, and how far the exposure spread across archived EHR and migration environments.

Aesto Health-style breaches also show why healthcare organizations can no longer afford fragmented security tooling. When PHI is spread across AWS infrastructure, EHR archives, data migration systems, databases, identities, endpoints, and provider-client environments, separate point tools create blind spots and slow investigations. A consolidated platform, like NIKSUN, that unifies SIEM, NDR, EDR, XDR, Threat Intelligence, SOAR, Vulnerability Management, Network Forensics, Packet Capture, Cloud Monitoring, and Compliance Reporting gives teams one place to detect the intrusion, reconstruct the timeline, identify what data was exfiltrated, and prove which clients were affected. Instead of jumping between disconnected dashboards while regulators, patients, and providers wait for answers, healthcare technology companies can use a single security data lake to accelerate HIPAA response, reduce breach scope, eliminate redundant tools, and turn cybersecurity from reactive investigation into continuous protection. Read more about this story on our LinkedIn page

We use cookies to offer you a better browsing experience and to analyze site traffic. By using our site, you consent to our use of cookies.

Essential Cookies
Site Analytics