AI News Feed
Market watch
Cybersecurity

Aesto Health Data Breach Affects Over 9.5 Million Patients

Aesto Health disclosed a cyberattack on its AWS systems that exposed personal, financial and medical data of more than 9.5 million patients, marking the second-largest healthcare breach of 2026.

The breach affected more than two dozen of Aesto Health's clients, including Village Practice Management, Everside Health, and Together Women's Health Medical Group. In a filing with the U.S. Department of Health and Human Services' Office for Civil Rights, the company detailed that attackers accessed personally identifiable information, Social Security numbers, partial dates of birth, driver's license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims and billing information, as well as health insurance information.

Aesto Health, which helps other healthcare organizations manage medical data and transition electronic health records systems, took more than half a year to report the incident after discovering it, according to the report. No evidence has emerged so far that the stolen data has been leaked on the dark web or used in criminal activity. The company is offering credit monitoring and identity theft protection services to all affected individuals.

The breach is the second-largest of its kind this year, behind an attack on DentaQuest that exposed 15 million records, according to HIPAA Journal.