A massive data breach at Aesto Health has compromised sensitive information for over 9.5 million individuals, sparking concerns about the security of healthcare organizations’ patient data. The company, which provides software-as-a-service solutions to help healthcare providers manage electronic health records, disclosed the attack in a recent statement.
The breach occurred between December 2 and 18, 2025, when an unauthorized actor accessed and potentially acquired sensitive information from Aesto’s network. This included full names, dates of birth, medical details, driver’s license numbers, financial account numbers, health insurance information, and even Social Security numbers for a staggering number of patients. The affected individuals are spread across various healthcare providers, including VillageMD, Everside Health (Marathon Health), Marana Health, and Together Women’s Health.
It’s worth noting that Aesto Health uses Amazon Web Services (AWS) to host its infrastructure, which was compromised during the breach. This incident highlights the importance of robust security measures for cloud-based services, particularly those handling sensitive healthcare data. The company has since informed impacted individuals about the breach and is offering 24-month identity theft protection and credit monitoring services through Experian.
This latest development follows a string of similar incidents at other healthtech software companies in recent months. It’s clear that attackers are targeting these organizations with increasing frequency, highlighting the need for enhanced security measures to protect patient data. While no threat groups have publicly claimed responsibility for the Aesto Health attack, the incident serves as a stark reminder of the importance of robust cybersecurity practices.
Aesto Health is just one of many companies in the healthcare sector to fall victim to cyberattacks this year. In fact, the Blue Report 2026 found that once attackers gain valid credentials, prevention measures are significantly less effective. This highlights the need for organizations to adopt a more comprehensive approach to security, focusing on techniques beyond traditional prevention methods.
As the number of data breaches continues to rise in the healthcare sector, it’s essential for individuals and organizations to take proactive steps to protect sensitive information. Patients should remain vigilant and be aware of potential risks associated with their personal data. Healthcare providers, meanwhile, must prioritize robust cybersecurity measures to safeguard patient data and prevent similar incidents from occurring in the future.
In light of this incident, we recommend that patients take immediate action to monitor their credit reports and financial accounts for any suspicious activity. Additionally, healthcare organizations should review their security protocols and consider implementing additional measures to protect against unauthorized access to sensitive information. By taking a proactive approach to cybersecurity, we can mitigate the risk of data breaches and ensure the integrity of patient data.
Source: Bleeping Computer — 2026-09-01