Alabama-Based Health Tech Firm Breached, Affecting 9.5 Million Patients – Names, SSNs, Health Records at Risk

An Alabama company that stores and moves patient records is warning that personal and medical data for about 9.5 million people may have been accessed in a cyberattack.
Aesto Health told the HHS Office for Civil Rights that 9,540,683 people are involved, reports SecurityWeek.
Aesto says unauthorized actors reached part of its Amazon Web Services systems. It detected the incident on or about December 18th of 2025. A later review found the access window ran from December 2nd to December 18th of 2025.
Says Aesto,
“On or about December 18, 2025, Aesto experienced a network security incident that impacted a limited portion of our Amazon Web Services infrastructure.”
The company says the files may have included names, Social Security numbers, driver’s license numbers, financial account numbers, taxpayer IDs, health records, medical histories, claims and billing data and insurance details. Social Security numbers were involved only for some people. The information varied by person.
Patients of at least 30 clients may be in the set, including Village Practice Management, Everside Health and Together Women’s Health Medical Group. Aesto says it has no evidence of identity theft or financial fraud. It is offering credit monitoring and identity theft protection.
… Continue reading the full article at the original source below.

