Business Associate Hacking Incident Affects 9.5 Million Patients
Aesto LLC, doing business as Aesto Health, a business associate that provides healthcare data management services and software to HIPAA-covered entities, has experienced a massive data breach affecting more than 9.5 million individuals. The data breach was reported to the HHS’ Office for Civil Rights in mid-August; however, it has only just been listed on the OCR breach portal. With at least 9,540,683 individuals known to be affected, the hacking incident ranks as the 12th largest healthcare data breach of all time, and the second-largest healthcare data breach of the year.
The hacking incident was first announced by Aesto Health on June 24, 2026. Aesto explained that an unauthorized third party accessed a limited portion of its Amazon Web Services (AWS) infrastructure. The forensic investigation determined that hackers had access to its AWS infrastructure between December 2, 2025 and December 18, 2025, during which time files may have been accessed and/or copied. The files were reviewed, and on May 26, 2026, Aesto Health confirmed that the information potentially compromised in the incident included the protected health information of patients of some of its HIPAA-covered entity clients. The affected covered entity clients started to be notified on June 26, 2026, of which around three dozen have confirmed that they have been affected. The affected individuals started to be notified on August 21, 2026.
Data exposed in the incident included full names, dates of birth, medical information, driver’s license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. Credit monitoring and identity theft protection services have been offered to the affected individuals for 24 months. The threat group behind the attack is unclear. No group appears to have claimed responsibility for the attack.
The Aesto Health data breach is one of several mega healthcare data breaches to be reported this year – data breaches that have each affected millions of individuals. In addition to the Aesto Health data breach, mega data breaches have been announced by DentaQuest, the largest of the year to date, affecting an estimated 15 million individuals.
Luxema Imaging, a nationwide diagnostic imaging services provider, reported a data breach affecting more than 5.8 million individuals; the healthcare provider AdaptHealth experienced a 4.1 million-record data breach; the medical device company Medtronic experienced a data breach affecting 3.8 million individuals, as did the practice management software company Unlimited Technology Systems. Healthcare technology company CareCloud reported a data breach affecting 3.7 million individuals, and the genetic testing company Baylor Genetics recently announced a breach that has affected 2.8 million individuals.