Aesto Health says data breach affects over 9.5 million patients

A massive data breach at Aesto Health has compromised the sensitive information of over 9.5 million individuals, highlighting the ongoing vulnerabilities in the healthcare industry’s digital infrastructure. The attack, which occurred between December 2 and December 18 last year, involved an unauthorized actor accessing protected health information stored within Aesto’s network.

Aesto Health provides software-as-a-service solutions that help healthcare organizations manage patient data, making it a critical component of the healthcare sector’s digital ecosystem. The company first acknowledged the breach on June 24, but only recently began notifying affected individuals about the incident and offering them credit monitoring services through Experian. This delayed response has sparked concerns among security experts and lawmakers, who are calling for greater transparency and accountability in such incidents.

The data breach is particularly concerning due to its scope and the sensitive information that was compromised. Aesto Health revealed that the attacker accessed full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, government identification numbers, and Social Security numbers for 9,540,683 individuals. This level of detail makes it easier for attackers to commit identity theft or sell stolen data on the dark web.

The Aesto Health breach is not an isolated incident; a recent report by HIPAA Journal found that it indirectly affects 29 healthcare providers, including VillageMD and Everside Health (Marathon Health). In fact, this attack follows a string of similar incidents at other healthtech software companies in recent months. While no threat group has publicly claimed responsibility for the Aesto Health breach, security experts warn that these attacks often go unreported or misattributed.

The incident underscores the need for healthcare organizations to prioritize cybersecurity and implement robust measures to protect sensitive patient data. With the rise of cloud-based solutions, attackers are increasingly targeting vulnerable infrastructure to gain access to valuable information. As we’ve seen with other breaches, a single vulnerability can have far-reaching consequences, compromising not just one organization but also its partners and clients.

In light of this incident, it’s essential for individuals whose data was compromised to take proactive steps to protect themselves from potential identity theft or financial fraud. While Aesto Health has offered credit monitoring services through Experian, users should remain vigilant and regularly review their account statements and credit reports for any suspicious activity. By staying informed and taking preventive measures, we can minimize the impact of such breaches and ensure that our sensitive data remains secure.


Source: Bleeping Computer — 2026-09-01