Data Breach
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health
TL;DR
Third-party healthcare data migration vendor Aesto Health suffered unauthorized access to its AWS environment in December 2025, compromising names, SSNs, medical data, and more for an estimated 9.54 million patients tied to 30 provider clients including Everside Health. The breach appeared on the HHS portal September 3, 2026, following a forensic investigation that concluded May 26, 2026. No enforcement action or fine has been announced.
A cyberattack on Aesto Health's Amazon Web Services infrastructure exposed the records of roughly 9.54 million patients across 30 covered entity clients. Here is what compliance officers need to know about third-party risk, BAA oversight, and the breach timeline.
One vendor. Thirty provider clients. Roughly 9.54 million patients with their Social Security numbers, medical records, and financial account details now potentially in the wrong hands.
Aesto Health, a healthcare data migration company operating as a business associate, was added to the HHS breach portal on September 3, 2026, with a reported count of 9,540,683 affected individuals. The unauthorized access occurred inside Aesto's Amazon Web Services environment between December 2 and December 18, 2025. The full scope of the breach was not confirmed until a forensic investigation concluded on May 26, 2026. Everside Health, a direct primary care provider, is among the 30 covered entity clients identified as affected.
This is a breach disclosure, not an OCR enforcement action. No fine, corrective action plan, or resolution agreement has been announced as of publication.
What Happened
Between December 2 and December 18, 2025, an unauthorized party gained access to Aesto Health's AWS infrastructure. Aesto provides data migration services to healthcare organizations, meaning it routinely handles large volumes of protected health information (PHI) on behalf of covered entities.
The categories of data reported as exposed are broad and serious:
- Full names
- Dates of birth
- Social Security numbers
- Medical information
- Financial account numbers
- Driver's license numbers
- Health insurance information
The combination of clinical and financial identifiers in a single breach event significantly elevates the risk of identity theft and medical fraud for affected patients.
The forensic investigation took roughly five months to complete, concluding May 26, 2026. The HHS breach portal entry reflects the final confirmed patient count of approximately 9,540,683 across 30 provider clients.
Warning
A five-month forensic investigation window means some covered entity clients may have faced compressed timelines for their own 60-day HIPAA breach notification obligations. Covered entities should review their BAAs to confirm how and when their business associates are required to report incidents, and whether those timelines were met in this case.
Why This Breach Pattern Is a HIPAA Compliance Problem
The Aesto Health incident is a clear example of cascading third-party risk: a single business associate's security failure propagating across dozens of covered entities and nearly ten million patients simultaneously.
HIPAA's Security Rule requires covered entities to manage the risks posed by their business associates.
Under 45 CFR §164.308(b)(1), covered entities must obtain satisfactory assurances from business associates that the associate will appropriately safeguard PHI. Those assurances must be documented in a business associate agreement (BAA).
Under 45 CFR §164.314(a)(1), the BAA itself must include specific provisions governing how the business associate will report security incidents, including breaches, to the covered entity.
Under 45 CFR §164.410, a business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 days after discovery. The covered entity's own 60-day notification clock to affected individuals, under 45 CFR §164.404, typically begins running from the date the business associate discovered the breach, not the date the covered entity was notified.
When a vendor like Aesto Health takes months to confirm the full scope of a December 2025 breach, covered entities face real exposure if their notification timelines slip as a result.
The Business Associate Agreement Is Not a Set-It-and-Forget-It Document
Many organizations treat the BAA as a checkbox, signed once during vendor onboarding and rarely revisited. The Aesto Health breach illustrates exactly why that approach is inadequate.
A well-structured BAA should address:
Incident reporting timelines. The agreement should specify how quickly the business associate must report a suspected or confirmed security incident, not just a confirmed breach. Waiting for forensic certainty before notifying the covered entity can compress the covered entity's own response window.
Access to forensic findings. Covered entities should have the right to receive detailed incident reports, not just summary notices. Understanding what data was accessed, how, and for how long is essential for accurate breach risk assessments.
Subcontractor obligations. Under 45 CFR §164.308(b)(4), business associates must ensure that subcontractors who handle PHI on their behalf also provide satisfactory security assurances. If Aesto used any downstream vendors with access to its AWS environment, those relationships require scrutiny as well.
Right to audit. The BAA should preserve the covered entity's right to verify the business associate's security practices, not simply accept attestations at face value.
Third-Party Risk Management Is Not Optional
For the 30 covered entity clients named in this breach, the immediate compliance priorities are clear: confirm breach notification obligations were met, assess whether patient notification letters have been or are being sent, and document the risk assessment that supports those notifications.
For the broader compliance community, the Aesto Health event is a prompt to examine vendor portfolios with a sharper eye.
Questions worth asking now:
- Which of your business associates handle large-scale PHI as their core function, such as data migration, interoperability, or cloud hosting?
- Do your BAAs reflect current regulatory requirements, or were they drafted years ago without updates?
- Have you asked your data-handling vendors about their cloud infrastructure security controls, including how access to environments like AWS is monitored and restricted?
- Do you have a documented process for responding when a business associate reports an incident, including how you track notification deadlines?
A data migration vendor, almost by definition, aggregates PHI from many sources into a single environment. That concentration of records creates an attractive target and a catastrophic blast radius when something goes wrong.
What We Do Not Yet Know
The public record on this breach remains limited. As of publication, it is not known:
- Which specific covered entity clients beyond Everside Health are among the 30 listed
- Whether all 30 clients have completed or initiated patient notification
- How the unauthorized access to Aesto's AWS environment was initially achieved
- Whether any of the exposed data has been confirmed as misused
Medcomply.ai will update this article as additional information becomes available through the HHS portal or other reliable public sources.
The Aesto Health breach is a textbook illustration of third-party risk concentration: one vendor's compromised AWS environment cascading into a reported 9.54 million patient records across 30 provider clients. Covered entities cannot outsource their HIPAA liability along with their data workflows. A signed BAA is necessary but not sufficient. The agreement must contain enforceable incident reporting timelines, and covered entities must actively monitor whether their business associates are meeting those obligations, especially when cloud-hosted PHI is involved.
Sources & citations
- The Daily Hodl: Healthcare Firm Breach Exposes 9,500,000 Patient RecordsOpen
All content verified against official HHS guidance and the Code of Federal Regulations.
Frequently asked questions
What is Aesto Health and what does it do?▾
How many patients and providers were affected by the Aesto Health breach?▾
What types of data were exposed in the Aesto Health breach?▾
Has HHS OCR issued a fine or taken enforcement action over this breach?▾
What should covered entities do if they use a third-party data migration vendor like Aesto Health?▾
Related intelligence
Data Breach
TheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure
4 min read
Data Breach
ShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII
5 min read
Data Breach
CareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients
5 min read
Not legal advice. medcomply.ai provides compliance intelligence for educational and operational planning. Consult qualified counsel for legal interpretation.