Health data of more than 9.5 million people leaked from Aesto record system

The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.
The Birmingham, Alabama-based company previously warned customers about the attack in June but had not shared information about the scope. On TKDAY, it notified the Department of Health and Human Services that millions were impacted by the data breach.
The stolen data includes names, Social Security numbers, medical information, driver’s license numbers, financial account numbers, health insurance data and more.
In its June statement, the company said an investigation revealed that hackers broke into its Amazon Web Services infrastructure between December 2 and December 18, stealing troves of information related to patients of its customers.
Aesto provides data migration and archiving services to medical facilities upgrading their technology or switching electronic health record vendors and supports healthcare groups purchased by other companies. At least 30 healthcare organizations were affected by the Aesto breach.
Aesto filed breach notices in several states on behalf of its customers, including Together Women's Health in Texas and California.
No hacking group has publicly taken credit for the attack on Aesto and the company did not respond to requests for comment.
Millions of people have had sensitive information leaked through cyberattacks on healthcare data firms this year. Baylor Genetics also told federal regulators this week that more than 2.8 million people had medical testing information, laboratory test results and more stolen during a cyber incident in June.
Another 3.7 million people were impacted by a March cybersecurity incident involving electronic health records giant CareCloud.
Healthcare companies McKesson, Nutex, Paylogix all announced cyberattacks over the last two weeks that involved patient and customer data.
Park Dental Partners warned the Securities and Exchange Commission (SEC) on Tuesday night of a cyberattack last week that forced them to initiate incident response protocols and hire outside cybersecurity experts.
While the attack did not impact the operations of the company, it decided to report the incident to the SEC “due to the possible access of patient data.”
References in this story
- Notice of Data Security Incident-12-18-25 www.aestohealth.com
- Submitted Breach Notification Sample oag.ca.gov
- Security Update - Baylor Genetics www.baylorgenetics.com
- Electronic health record company CareCloud says 3.7 million people affected by breach therecord.media Healthcare software firm CareCloud filed documents with the Department of Health and Human Services confirming that 3,756,469 people had information leaked after a hacker spent eight hours in one of the company’s…
- Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack therecord.media The pharmaceutical and healthcare technology company McKesson informed regulators it is in the early stages of investigating a cybersecurity incident involving an unnamed third-party application.
- Healthcare facilities operator Nutex says patient, employee data stolen in August incident therecord.media Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
- Employee benefits platform Paylogix says hackers stole financial and health therecord.media The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



