The Aesto Health breach: 9.5 million patients, one vendor

A records company most patients have never heard of held their Social Security numbers, insurance details and medical files for dozens of hospitals and clinics. Here is who is involved, why the letter took eight months, and what to lock down now.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn
Quick answer

Aesto Health archives and migrates patient records for healthcare providers. Between 2 and 18 December 2025 an intruder reached part of its cloud environment, and the company has reported 9,540,683 affected people to federal regulators. Depending on the person, the data includes Social Security numbers, dates of birth, government ID, insurance and financial account numbers, and medical records. Letters began arriving in late August 2026 under the names of the patients’ own providers. The useful response is a credit freeze, an IRS Identity Protection PIN, the free monitoring in the letter, and a close read of your insurer’s statements.

From the intrusion to your mailbox

Eight months passed between the break-in and the first patient letters. This is where the time went.

WhenWhat happened
2–18 December 2025An unauthorized party has access to part of Aesto’s Amazon Web Services environment.
18 December 2025Aesto detects the activity and starts an investigation.
26 May 2026After a forensic review and a manual read of the documents involved, Aesto confirms which patient data may have been taken.
26 June 2026Aesto starts telling the healthcare providers whose records it held.
Late August 2026Letters start reaching patients, and the federal HHS breach portal lists the incident at 9,540,683 people.

Providers whose patients are involved

These are the client organisations named in reporting on 1 September 2026. If you were ever a patient of one of them, the letter may reach you under that name. The list covers hospitals, community health centres, women’s health and orthopaedic practices across several states, and it may not be complete.

  • Avina Women’s Care
  • Edwards County Medical Center
  • Effingham Obstetrics & Gynecology Associates
  • Ellenville Regional Hospital
  • Everside Health
  • Gila Health Resources
  • Graham County Hospital
  • Greenwood County Hospital
  • Henry County Hospital
  • Kaniksu Community Health
  • Little River Memorial Hospital
  • Livara Health Medical Group (formerly SpineZone)
  • Lone Star Community Health Center
  • Main Street Medical Services
  • Marana Health
  • Mid-South OB-GYN
  • Midtown Community Health Center
  • Mineral Community Hospital
  • Monroe Health Center
  • Murfreesboro Medical Clinic
  • My Doctor, LLC
  • Nebraska Orthopedic Center
  • Northern Inyo Hospital
  • North Florida Women’s Care
  • Park West Health Systems
  • Quincy Valley Medical Center
  • Holton Community Hospital
  • Shenandoah Valley Medical System
  • Stanislaus County Health Services Agency
  • Sterling Health Solutions
  • Surgeons Choice Medical Center
  • Texas Spine Consultants
  • Together Women’s Health (including its Alabama group)
  • Advanced Women’s Care (Valley Perinatal Services)
  • Village Medical / VillageMD
  • Women’s Health Associates

Sources: the HHS Office for Civil Rights breach portal; Aesto Health’s notice as reported by HIPAA Journal and BleepingComputer, 1 September 2026; SecurityWeek, The Record and Tom’s Guide, 1–4 September 2026.

1. What happened, in order

For just over two weeks in December 2025 someone had access to part of the Amazon Web Services environment where Aesto Health, a Birmingham, Alabama company, keeps patient records for its clients. Aesto spotted it on 18 December. Working out whose data was involved took until 26 May 2026, because the review included reading the documents themselves, and the company began telling its client providers on 26 June. The patients came last: letters started arriving in the second half of August, roughly eight months after the intrusion, and the federal breach portal now puts the count at 9,540,683 people. Aesto says it has seen no evidence of identity theft or fraud linked to the incident. No group has claimed it.

2. Why a clinic you left years ago may be writing to you

Aesto’s business is data migration, legacy archiving and record exchange between electronic health record systems. When a practice switches to a new system, the old records have to go somewhere, and a company like this keeps them readable. So the patients in this file are not only current ones: anyone whose chart was moved or archived through Aesto can be in it, including people who stopped seeing that provider long ago. That is why the letter arrives with the name of a hospital or women’s clinic on the envelope, and why there is no Aesto account anywhere for you to log into or secure.

3. What was taken, and why it is the expensive kind

The reported fields are close to a complete identity: name, date of birth, Social Security or taxpayer identification number, driver’s licence or other government ID, health insurance details, financial account numbers, and medical information including diagnoses and claims history. Each piece is a different kind of problem. The Social Security number opens new credit and tax refunds in your name. The insurance details are enough to bill treatment you never had. The account numbers support payment fraud and very convincing calls from “your bank”. None of it can be reset the way a password can, which is why the steps below are about locking things down rather than changing anything.

4. What is worth doing this week

Freeze your credit at Equifax, Experian and TransUnion; it is free, takes a few minutes online at each, and blocks new accounts opened with your number. Request an IRS Identity Protection PIN at irs.gov, since a stolen Social Security or taxpayer ID number is how fraudulent returns get filed. Enrol in the monitoring your letter offers before its deadline. Read the next few explanation-of-benefits statements from your insurer line by line, looking for visits or prescriptions that are not yours. And if the letter lists a financial account, ask the bank to watch it, or to replace the number. Our medical data breach guide covers the insurance and medical-records side in more detail.

5. The calls and emails that follow a breach like this

A breach this size is news, and the news is the script. Expect calls from someone claiming to be your clinic’s billing office or Aesto itself, offering to “verify your identity” or “activate protection” if you read out your Social Security number. Expect texts pointing to claim sites that are not run by any court, and lawsuit ads that ask for more than a lawyer needs. The genuine parties already hold your details and do not ring you to collect them. If a message wants your number, your insurance ID or a one-time code, hang up and call back on a number you looked up yourself.

6. Lawsuits and settlements

Law firms including Edelson Lechtzin have announced investigations, which is the normal first step and does not mean a case has been filed or money set aside. If a class action is filed and later settles, a court-approved administrator runs the claims process, usually many months later, and the payouts depend on documented losses and time spent. Keep the letter, and keep notes of anything you do in response, such as freezes, calls or fraud reports, with dates. Our settlement claims guide explains what that paperwork is worth once a claim window opens.

7. The part that outlives the letter

A Social Security number and a date of birth stay the same for life, so this file stays useful to whoever has it long after the news fades. What you can shrink is everything that sits next to it. Your address, phone number and relatives are already listed on people-search and data-broker sites, and those listings are how a stolen number gets matched to a person who can be phoned, mailed or impersonated. Taking them down, and checking that they stay down, is the step with the longest effect. For the full sequence after any breach, see our post-breach guide, and for reading the notice itself, the notification-letter guide.

See what else is published about you

The address and phone number that turn a stolen Social Security number into a phone call are also sold by 499 broker and people-search sites. PersProtect finds where you are listed, files the removals and keeps checking that they stay down. The scan is free.

Check my exposure — free →
Common questions

The Aesto Health breach, answered

I have never heard of Aesto Health. Why did I get a letter?

Because your doctor, hospital or clinic used it. Aesto moves and archives patient records for healthcare providers, mostly when a practice replaces its electronic health record system, and it held those records on the provider’s behalf. The letter usually carries the name of the practice you know, with Aesto named inside as the company that was breached. That is how a vendor you never chose ends up holding your Social Security number.

Is the Aesto Health breach letter real or a scam?

The breach is real and letters did start going out in late August 2026, so a paper notice naming Aesto and one of its client providers is plausible. Check it by the route, not the wording: look up your provider’s phone number yourself and ask whether it sent the notice, and enrol in any credit monitoring by typing the monitoring company’s address rather than following a link from an email or text. A genuine letter never asks you to reply with your Social Security number.

What information was exposed in the Aesto breach?

It varies by person. The categories reported are full names, dates of birth, medical information and health records, health insurance details, driver’s licence and other government ID numbers, financial account numbers, taxpayer identification numbers and Social Security numbers. Your letter should say which of those applied to you, and that is the list to act on.

How many people were affected by the Aesto Health data breach?

Aesto reported 9,540,683 people to the HHS Office for Civil Rights, which makes it the second-largest healthcare breach confirmed in 2026 so far, behind DentaQuest. The patients came through at least 29 client providers by BleepingComputer’s count, and HIPAA Journal’s list names 37 organisations.

Can I check my email to see if I am in it?

Not usefully. No group has claimed the attack and the data has not been reported as published, so an email lookup has nothing to match against. The letter is the confirmation. If you were a patient of one of the named providers, especially one that changed record systems in the last few years, act on the assumption that you may be in it.

Should I sign up for the free credit monitoring?

Yes, it costs nothing and it is the one part of the response Aesto pays for. Letters quoted in coverage offer Experian IdentityWorks, with the enrolment code and a deadline printed on the letter, and some versions name TransUnion instead. Monitoring tells you after something has happened, though, so pair it with a credit freeze at all three bureaus, which stops new accounts being opened at all.

Is there an Aesto Health class action lawsuit?

Several law firms have announced investigations, and no court has approved anything yet. Talking to one costs nothing, but be careful with the ads: a genuine firm does not need your full Social Security number in a web form to register interest. Any money for patients would come through a settlement administrator much later, and our list of open settlements covers the ones taking claims today.

Your number stays the same. Your listings do not have to.

See which sites publish your name, address and phone number right now. It is free and takes about a minute.

Run my free exposure scan →