Skip to content
>_ITDITDWeb Security Platform

Security Guides

A breach notice from a company you've never heard of: the Aesto Health breach affecting 9.5 million people and the problem with medical record archives

Healthcare data archiving vendor Aesto Health reported 9,540,683 people affected to HHS after unauthorized access to its cloud environment in December 2025. What its notice and public records say, what to do if you got a letter, and what providers should check.

Published 2026-09-30 Updated 2026-09-30 Last verified 2026-09-30 13 min read

For: anyone in the US who has seen a healthcare provider and received a letter from Aesto (Aesto Health), a company they don't recognize, their families, and providers and businesses that entrust patient records to outside vendors. This article is based on Aesto's official notice, the US Department of Health and Human Services (HHS) breach portal, a notice letter filed with a state attorney general, and guidance and regulations from US agencies (the FTC, the IRS and federal rules). It does not cover attack methods.

What people who got a letter should do today

1

Check the notice page for your provider

Aesto's notice says it is provided on behalf of the covered entities and has a section identifying them. The sample letter filed with the California Attorney General is likewise sent by Aesto on behalf of a client provider and names that provider. Don't bin the letter just because you don't know the company; look for the name of a provider you've actually used.

2

Use only the number in the notice

The dedicated line is 833-918-8060 (Monday to Friday, 8 a.m. to 8 p.m. Central, excluding major US holidays), and the notice asks you to have its engagement number ready. The exposed data includes contact and insurance details, so don't trust calls or emails that say "this is Aesto" or "about your hospital's archived records" and ask for your SSN or account number (see what is phishing?).

3

Check what monitoring your own letter offers

In the sample letter filed with California, the client provider offers a complimentary 12-month credit monitoring membership. Because the provider is the one offering it, the details and deadline may differ from letter to letter. Follow the enrollment steps and deadline in your own letter.

4

Protect SSNs and ITINs: freeze credit at all three bureaus and get an IRS IP PIN

A credit freeze is free and has to be placed with each of Equifax, Experian and TransUnion. An IRS IP PIN is a six-digit number that, per the IRS, prevents someone else from filing a tax return using your SSN or ITIN. ITINs are on the list of exposed data here, so this applies to people who file with an ITIN too. The IP PIN is valid for one calendar year, and a new one is generated each year. For the full US checklist, including children, see what DentaQuest members should do.

5

Medical and insurance information: read your benefit statements and request records

The FTC lists a bill or Explanation of Benefits statement for services you didn't get, or a collector calling about medical debt you don't owe, as signs of medical identity theft. Aesto's notice likewise suggests reviewing your EOB statements, following up on anything you don't recognize with your insurer or provider, and if necessary asking for copies of medical records from the date of the potential access to the present.

6

If a license or account number was involved, go to that door too

A driver's license number can be used in ways a credit freeze doesn't cover. The FTC's advice to contact your state motor vehicle agency is explained in the AssuranceAmerica breach. If a financial account number was involved, review your statements and tell your bank.

Patient (you)

You know the provider you saw

↓ care

Provider (covered entity)

Hands off migration and archiving of old records

↓ vendor

Archiving vendor (business associate)

Access in part of its cloud environment

The way back

Vendor → providers (from June 26, 2026) → patients (notice and letters issued by Aesto on the providers' behalf)

Patients never see the middle-to-right part

How patient records reach an archive, and how the notice comes back. Under HIPAA rules, a business associate notifies the provider and the provider notifies the individual (45 CFR 164.410 and 164.404). Here, Aesto issued the public notice and letters on the providers' behalf.

What happened (from Aesto's notice and public records)

The following is taken from Aesto's notice (dated June 24, 2026), the HHS Office for Civil Rights breach portal and the sample notice letter filed with the California Attorney General.

  1. On or about Dec. 2, 2025

    Per the company, the start of the period in which information may have been accessed or acquired.
  2. On or about Dec. 18

    The company detects and contains a network security incident affecting part of its cloud infrastructure, and begins an investigation with outside cybersecurity experts.
  3. May 26, 2026

    After a forensic investigation and manual document review, the company confirms the information involved.
  4. June 24

    The company publishes its notice.
  5. June 26

    The company begins notifying covered entity clients whose patient information was in the files potentially accessed or acquired.
  6. July 31

    Submission date on the HHS portal (9,540,683 affected).
  7. August 25

    Date of the sample notice letter filed with the California Attorney General (for one client provider).
9,540,683
People affected (HHS Office for Civil Rights portal)
~17 days
Period of potential access (on or about Dec. 2–18, 2025)
Dec 2–18
Period of possible access and acquisition (2025, per the company's notice)
12 months
Free credit monitoring offered by the provider in the sample letter
What the company has disclosed
Company
Aesto, LLC (Aesto Health), Birmingham, Alabama. Provides healthcare data migration and archiving for covered entity clients
Environment affected
A limited portion of its cloud infrastructure
Information involved
Names, dates of birth, medical information, driver's license numbers, financial account numbers only, health insurance information, ITINs, other government ID numbers. SSNs for a limited number of people. Varies by individual
Misuse
The company says it has no evidence of identity theft or financial fraud related to the incident
HHS portal entry
Entity type: Business Associate / Type: Hacking/IT Incident / Location: Network Server
Contact
833-918-8060 (Monday to Friday, 8 a.m. to 8 p.m. Central, excluding major US holidays)

How to read the dates

From detection (on or about December 18, 2025) to confirming the information (May 26, 2026), the company says it ran a forensic investigation and a manual document review. The sample letter to individuals we found is dated August 25, 2026. The company says it spent that time on a forensic investigation and manual document review. This article doesn't evaluate that period, but what it means for readers is clear: now that you have the letter, assume not "nothing has happened yet" but "this may have been in someone else's hands for months", and get the freeze and checks done first.

Why did a company you've never heard of have your records?

Aesto describes its business as healthcare data migration and archiving. When a provider replaces its electronic health record or billing system, or merges into another organization, it can't simply throw away the old system's records. So it may hand the old records to an outside archiving service that keeps them available for lookup. Patients never see that move. They went to a hospital or clinic, and nobody tells them where the records went next.

Under US health privacy rules (HIPAA), such vendors are called business associates. Federal regulations set the order: when a business associate discovers a breach it notifies the provider (45 CFR 164.410), and the provider notifies the individual (45 CFR 164.404). That's why the letter arrives under Aesto's name, alongside the name of your provider.

What patients can't see

  • Which vendors their provider gave records to
  • How long those records are kept
  • The vendor's cloud environment
  • The notice arrives under a company name they've never heard

What patients can do

  • Check the provider list on the notice page
  • Make SSNs and ITINs useless with freezes and an IP PIN
  • Watch medical information through benefit statements and record copies
  • Only use the number printed in the notice

This site's view: archived records are rarely used, yet complete

An archive of old records is rarely opened in day-to-day care, yet it can hold a full set of name, date of birth, insurance, SSN and account number for years. The list of exposed data here looks a lot like that full set. The less often data is used, the less anyone remembers it's there, and the more likely it is to sit with no one deciding who keeps it and until when. Archiving is a way of postponing deletion, and every year of postponement makes the list longer if it leaks. For defenders, the first move comes before encryption strength: a list of what you've handed over, and a date to end it.

For providers and businesses: a vendor inventory and an end for archived records

1

Inventory every vendor that holds patient data

EHR and billing migrations, legacy record archives, billing services, document scanning. List every vendor holding patient data, whichever department signed the contract, and for each write down how many years and how many people, which fields (including SSNs or account numbers) and which cloud. In an incident spanning many client providers like this one, that list is where you start working out whether you're affected. The approach is the same as a security inventory.

2

Give archived records an end date

Confirm the retention periods required by law and contract, and put a procedure for deleting records past their date into the contract and into operations. Federal regulations require business associate contracts to provide that, at termination, the business associate will, if feasible, return or destroy all protected health information and retain no copies (45 CFR 164.504(e)(2)(ii)(J)). When a contract ends, confirm that the return or destruction actually happened.

3

Put less into the archive

When moving records off an old system, ask field by field whether SSNs and account numbers really need to move too. Dropping fields you don't need for lookup shrinks what can leak. For retention and backups in general, see backup essentials.

4

Be able to say quickly whose records are in there

The company says confirming the information involved took a manual document review. If you know which files hold which people's records and which fields for everything you've handed over, you can identify affected people faster after an incident and plan how to reach those with outdated contact details. For the overall approach, see the minimum security baseline for organizations.

Sources (public record)

The facts in this article are based on the public information below. Press estimates and speculation about undisclosed causes are not used. Healthcare providers are described by role in this article.

  • Aesto, LLC d/b/a Aesto Health, "Notice of Data Security Incident" (June 24, 2026) — aestohealth.com
  • HHS Office for Civil Rights, "Breach Portal: Cases Currently Under Investigation" (Aesto, LLC: 9,540,683 affected; submitted July 31, 2026) — ocrportal.hhs.gov
  • California Attorney General, sample Aesto notice letter (filed for one client provider, August 25, 2026) — oag.ca.gov
  • Code of Federal Regulations, 45 CFR 164.404 and 164.410 (breach notification) and 164.504(e) (business associate contracts) — ecfr.gov
  • Federal Trade Commission, "What To Know About Medical Identity Theft" — consumer.ftc.gov / "Credit Freezes and Fraud Alerts" — consumer.ftc.gov / IdentityTheft.gov
  • Internal Revenue Service, "Get an identity protection PIN" — irs.gov

Update history

2026-09-30: First version, based on Aesto's notice (dated June 24, 2026), the HHS Office for Civil Rights breach portal (submitted July 31, 2026), the sample notice letter filed with the California Attorney General, FTC and IRS guidance, and federal regulations. We will update it if the company or regulators publish more.

FAQ

QWhat is Aesto Health?
A

According to its notice, Aesto, LLC (Aesto Health), based in Birmingham, Alabama, provides healthcare data migration and archiving services for its clients, which HIPAA calls covered entities (healthcare providers and similar organizations). It isn't a company patients deal with directly, which is why many recipients won't recognize the name.

QWhat happened?
A

Aesto says that on or about December 18, 2025, it experienced a network security incident that impacted a limited portion of its cloud infrastructure. It contained the incident and investigated, and after an extensive forensic investigation and manual document review it confirmed on May 26, 2026 that, between on or about December 2 and December 18, 2025, protected health information of patients of various covered entity clients may have been accessed and/or acquired by an unauthorized actor.

QHow many people were affected?
A

The HHS Office for Civil Rights breach portal lists Aesto, LLC (entity type: Business Associate) with 9,540,683 individuals affected, a submission date of July 31, 2026, breach type 'Hacking/IT Incident' and location 'Network Server'.

QWhat information was exposed?
A

Aesto's notice lists full names, dates of birth, medical information, driver's license numbers, financial account numbers only, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. The elements varied by individual, and Social Security numbers were potentially involved for a limited number of individuals.

QWhy did the notice take so long?
A

Aesto says it detected the incident on or about December 18, 2025, and confirmed the information involved on May 26, 2026, after an extensive forensic investigation and manual document review. It began notifying its covered entity clients on June 26, 2026. This article does not evaluate that period; it only reports the dates in the company's notice and public records.

QHow do I find out whether I'm affected?
A

Aesto's notice says it is provided on behalf of the covered entities and includes a section identifying them. Check whether a provider you've used is listed. If you're unsure, call the dedicated line in the notice, 833-918-8060 (Monday to Friday, 8 a.m. to 8 p.m. Central, excluding major US holidays), with the engagement number given in the notice.

QI got a letter. What should I do?
A

If your letter offers free credit monitoring, enroll before its deadline. Place a credit freeze with Equifax, Experian and TransUnion, get an IRS IP PIN (it works for an SSN or an ITIN), and check your Explanation of Benefits statements for care you didn't receive. If your driver's license number was involved, contact your state motor vehicle agency; if a financial account number was involved, contact your bank.