Heallthcare technology company based in Birmingham, Alabama, Aesto Health, reported a data breach that affected more than two dozen healthcare provider clients after an unauthorized third party accessed part of the company’s Amazon Web Services (AWS) environment between December 2 and December 18, 2025.
Aesto Health provides legacy data archiving, secure data migration, and electronic health record (EHR) exchanges for healthcare providers. A security incident was identified on or around December 18, 2025, involving part of Aesto Health’s AWS infrastructure. Third-party cybersecurity experts investigated the incident and confirmed that an unauthorized third party had accessed the AWS environment between December 2 and December 18, 2025. A review of the affected infrastructure confirmed that it contained personally identifiable information and protected health information (PHI).
Information Involved
The information contained in the affected infrastructure included full names, partial birth dates, state ID numbers, Social Security numbers, driver’s license numbers, taxpayer ID numbers, financial account numbers, health records, medical histories, claims and billing data, and medical insurance information.
Aesto Health stated that it had taken steps to protect the sensitive information in its possession and evalaution of its security practices is in progress. Credit monitoring and identity theft protection services have been made available.
Healthcare Provider Clients Affected
More than two dozen healthcare provider clients are known to have been affected by the incident. The clients started receiving notification on June 26, 2026.
The healthcare providers identified as affected include Effingham Obstetrics & Gynecology Associates, PLLC, Edwards County Medical Center, Everside Health, Gila Health Resources, LLC, Ellenville Regional Hospital, Greenwood County Hospital, Graham County Hospital, Little River Memorial Hospital, Henry County Hospital, Nebraska Orthopedic Center, P.C, Main Street Medical Services, PLLC, Mid-South OB-GYN, PLLC, Marana Health, Midtown Community Health Center, Monroe Health Center, Missoula Community Health Services Inc., doing business as Mineral Community Hospital, My Doctor, LLC, Park West Health Systems, Inc., Rural Health Resources of Jackson County Inc. doing business as Holton Community Hospital, Quincy Valley Medical Center, Shenandoah Valley Medical System Inc., Sterling Health Solutions, Stanislaus County Health Services Agency, Texas Spine Consultants, LLP, Together Women’s Health Medical Group, PC, Village Practice Management (Village Medical; VillageMD), and Women’s Health Associates, Inc.
Other healthcare providers may also have been affected.
Reported Number of Individuals Affected
The number of affected individuals has been reported through multiple sources because affected healthcare provider clients have also reported the incident themselves. Some affected clients have reported that tens of thousands of their patients were involved. Village Practice Management confirmed that more than 25,000 of its patients were affected. Everside Health reported approximately 22,000 affected individuals in Washington alone.
State Attorney General breach listings identified at least 80,622 affected South Carolina residents, 37,253 affected Washington residents, 731 affected Oregon residents, and 91 affected Vermont residents. The incident has affected hundreds of thousands of patients.
HIPAA Breach Notification Responsibilities
When a data breach occurs at a business associate of a HIPAA-covered entity, the affected covered entity remains responsible for ensuring that the requirements of the HIPAA Breach Notification Rule are met. The covered entity can delegate responsibility for issuing notification letters to the breached business associate. It can also issue notification letters itself.
The allocation of notification responsibilities contributes to differences in how affected individuals are reported when a business associate experiences a data breach. In the Aesto Health incident, affected healthcare provider clients have reported their own affected populations in addition to the information associated with state Attorney General breach listings.