Aesto Health recently disclosed a data breach affecting more than 9.5 million people. Aesto is a software company for healthcare organizations that produces solutions to help them organize patient data when replacing health records systems.Spotted by Bleeping Computer, the company first posted a notice of the attack on June 24 via its website. However, the actual incursion took place over two weeks in December of 2025. It apparently wasn't discovered until May 26 of this year."After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aesto’s network may have been accessed and/or acquired by an unauthorized actor," the notice reads.Apparently, the breach involved unauthorized access via Aesto's Amazon Web Services infrastructure.What was taken (Image credit: Blazej Lyjak/Shutterstock)In its report, Aesto Health confirmed that the breach affects 9,540,683 people. Unfortunately, that data included full names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer ID numbers, Social Security numbers and other government identification numbers.According to the HIPAA Journal, the breach spans 29 different organizations including Edwards County Medical Center, Marana Health, My Doctor, LLC, the Nebraska Orthopedic Center and Women's Health Associates.The company started informing impacted individuals of the breach on August 21, providing details about the incident and providing identity theft protection and credit monitoring via Experian.Get instant access to breaking news, the hottest reviews, great deals and helpful tips.As noted by Bleeping Computer, this incident follows an unfortunate series of breaches that have affected health care companies including CareCloud, Nutex Health, iRhythm and McKesson. The breaches have ranged in size from a couple of hundred thousand to millions of records.Per Aesto Health and our own review, no threat groups have publicly claimed the attack, unlike other recent ones claimed by the hacker group ShinyHunters.How to stay safe after a data breach (Image credit: Shutterstock)Check out the full list of companies from the HIPAA Journal, and if you've used any health care organization, you might receive a data breach notification letter from Aesto. If you do, take advantage of the Experian coverage. Keep an eye on your mailbox since notification letters arrive the old-fashioned way.Even if Aesto doesn't send you a notification letter, you may want to take advantage of one of the best identity theft protection services to protect your identity.While no one has claimed the attachment, a bad actor could use your information to launch targeted phishing attacks. Phishing emails could contain malicious links or even malware.Health companies appear especially vulnerable as the summer comes to a close, and every company should be taking this threat seriously. Hopefully, companies are bolstering their cybersecurity right now. Follow Tom's Guide on Google News and add us as a preferred source to get our up-to-date news, analysis, and reviews in your feeds. More from Tom's GuideWe put the best identity theft protection to the test to protect your entire digital life — these are the services I recommendHave you been 'Flocked'? Here's how to look up automatic license plate readers in your areaWe've tested the best antivirus software and these are the 5 I recommend right now
More than 9.5 million patient records affected by Aesto Health data breach: what you need to know
Full Article
Original Source
Read the full article at Tomsguide →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.