Aesto Health: AWS infrastructure incident affected 9.54 million people

The federal HHS OCR register lists an Aesto cyber incident involving 9,540,683 affected individuals. The company reported possible access to protected health information in part of its AWS infrastructure.

Aesto Health AWS incident affected 9,540,683 people, according to the U.S. Department of Health and Human Services HHS OCR federal register. A report by Aesto, LLC is listed as a “Hacking/IT Incident” involving a network server, with a filing date of July 31, 2026. It is a large-scale security case involving a vendor that works with clients’ health records.

Aesto previously said it detected unauthorized activity on December 18, 2025, in a limited part of its Amazon Web Services infrastructure. According to the company, a subsequent investigation found that an unauthorized person may have accessed or obtained patients’ protected health information from its clients during approximately December 2 through December 18, 2025.

Aesto Health AWS incident in the HHS register

The figure of 9,540,683 affected individuals comes from a report in the HHS Office for Civil Rights portal, which collects data on significant health data breaches. The register classifies the incident as a hacking or IT incident and identifies a network server as the location of the breach.

The scope of the case concerns people whose data Aesto processed for its clients. The company provides services related to the migration and archiving of health records, so the incident may affect data across multiple healthcare organizations. However, no complete public list of affected providers has been released.

The federal portal report itself confirms the number of potentially affected people, but does not describe how the breach occurred technically or the nature of the data that may have been available for specific individuals.

What data may have been affected

According to Aesto’s notice, the potentially affected data included:

  • names and dates of birth,
  • health information,
  • health insurance information,
  • certain financial identifiers,
  • certain government identifiers.

According to the company, Social Security numbers may have involved only a limited number of people. Aesto did not specify what combinations of data may have been present in the affected part of the infrastructure for individual patients.

The company said it contained the incident and engaged outside experts in the investigation. It also announced that it found no evidence of identity theft or financial fraud associated with the case. However, this statement does not mean it was independently confirmed whether the attacker actually exfiltrated or published the data.

Technical details and attacker identity remain unknown

Neither the public notice nor the HHS record identifies a specific vulnerability, intrusion technique or details about security fixes implemented after the incident. The attacker’s identity is also unknown, and no link to a specific ransomware or other cyber group has been confirmed.

Aesto also does not claim that access to all recorded data was proven. The company’s wording indicates that the data may have been made available to an unauthorized person or that the person may have obtained it during the approximately 16-day period in December 2025.

Why the scope of the case matters

Aesto Health AWS incident highlights the scale of the risk involving external providers that centrally process or transfer health records. A single breach in a vendor’s infrastructure can therefore affect patients at multiple healthcare organizations.

For affected individuals, the potential misuse of identifying and health information is particularly relevant. Because Aesto has not provided a complete public overview of the affected organizations or a detailed breakdown of the data by group, the practical level of risk for specific patients cannot be determined precisely from the available information.

Further developments may include the results of any review by HHS OCR, additional information from Aesto or affected healthcare providers, and possible public evidence of data misuse. So far, no public disclosure of the stolen data or claim of responsibility by the attackers has been confirmed.

Sources

  • HHS Office for Civil Rights Breach Portal – The federal register lists Aesto, LLC, 9,540,683 affected individuals, the Hacking/IT Incident category, a network server and a July 31, 2026, reporting date.
  • Aesto Health — Notice of Data Security Incident – The company’s initial notice describes the incident timeline, the affected part of the AWS infrastructure, possible data categories and the status of the investigation.
  • BleepingComputer – Corroborates that the newly published scope in the HHS report is 9,540,683 people and that Aesto’s public notice came earlier.

Verified and updated: 09/01/2026 22:35

Sharing