started · updated
Aesto Health data breach exposes 9.5 million medical records
Aesto Health, a U.S.-based healthcare technology company, has disclosed a major data breach that exposed the personal and protected health information (PHI) of approximately 9.54 million individuals.
The incident occurred between December 2 and December 18, 2025, when attackers gained unauthorized access to a portion of the company’s Amazon Web Services (AWS) infrastructure. The exposed data includes sensitive medical histories, names, and personally identifiable information (PII). Technical analysis suggests the breach may have involved compromised IAM credentials, S3 bucket misconfigurations, or AWS API vulnerabilities, which allowed for unauthorized API calls and data exfiltration.
Aesto Health, which specializes in electronic health record (EHR) exchanges and medical data archiving, confirmed the breach following an extensive forensic investigation. The incident has triggered mandatory reporting to the U.S. Department of Health and Human Services (HHS) and has led to multiple class-action lawsuits as of August 2026.
Entities
Aesto Health · Amazon Web Services · U.S. Department of Health and Human Services