BREACH2026-09-02T08:09:38.315513+00:005 min read

Your Doctor Used This Company to Store Your Records. Hackers Took 9.5 Million of Them.

A healthcare data company you've never heard of stored your medical records — and hackers quietly stole 9.5 million of them last December.

Your Doctor Used This Company to Store Your Records. Hackers Took 9.5 Million of Them.

The Company You've Never Heard of That Held Your Most Sensitive Data

You didn't choose Aesto Health. You never signed up for their service, never agreed to their terms, probably never saw their name until a letter showed up in your mailbox this August. But if you visited any of 30-plus medical practices or hospitals that hired them, Aesto Health had your Social Security number, your medical history, and your bank account details sitting in their cloud systems.

That's how the modern healthcare supply chain works. Your doctor doesn't manage your records alone. They outsource that to a vendor, who outsources storage to Amazon Web Services, and somewhere along that chain your most sensitive information lives in a place you've never seen and a company you've never heard of.

What Does Aesto Health Actually Do?

Aesto Health is an IT vendor. Their job is to store and migrate electronic health records on behalf of medical practices and hospitals. When a clinic moves to a new software system, or needs to archive old patient data, they call a company like Aesto. The records get uploaded to the cloud, managed by Aesto's team, and your doctor gets on with seeing patients.

It's an entirely normal part of how healthcare IT works. Most large medical systems use vendors like this. Most patients have no idea.

What Happened Between December 2 and 18, 2025?

Hackers gained access to Aesto's Amazon Web Services infrastructure. They had at least 16 days inside the system. During that window, they pulled data belonging to 9,540,683 people, making this the second-largest confirmed U.S. healthcare breach of 2026.

The stolen information includes:

  • Full names
  • Social Security numbers
  • Dates of birth
  • Driver's license numbers
  • Medical records
  • Health insurance details
  • Financial account numbers

That is not a partial picture of someone's identity. That is the full picture. With that combination of data, someone can open credit accounts in your name, file fraudulent tax returns, impersonate you to insurers, or sell your information to other criminals.

Eight Months. Then a Letter.

Aesto discovered the breach in December 2025. Patient notification letters were dated August 21, 2026, more than eight months later.

Federal law under HIPAA requires breach notifications to be sent within 60 days of discovery. Aesto missed that window by a wide margin, and multiple class-action lawsuits have already been filed in response.

Eight months is a long time for stolen data to move through criminal networks. By the time you got that letter, your information may have already been bought, sold, and used.

Aesto is offering affected individuals 24 months of free credit monitoring through Experian IdentityWorks. That is the standard response. It helps, but only if you act on it.

What Should You Do Right Now?

The most powerful tools available to you are free and take less than an hour. Don't wait for something bad to happen first.

  1. Freeze your credit at all three bureaus. Go directly to Equifax, Experian, and TransUnion and place a security freeze on your file. This is free. It prevents new credit accounts from being opened in your name without your knowledge. A freeze is stronger than monitoring, monitoring tells you after the fact, a freeze blocks the action.

  2. Activate the Experian offer if you received a notification letter. The 24-month IdentityWorks enrollment is free. Use it. It won't stop all fraud but it adds a layer of alerting.

  3. Check your Explanation of Benefits (EOB). If your insurer sends you EOBs after medical visits, review them. Medical identity theft, where someone uses your insurance to receive care, is harder to spot than financial fraud. Look for claims you don't recognize.

  4. File your taxes early this season. Tax fraud using stolen SSNs is common after large breaches. Filing early reduces the window for someone to file a fraudulent return under your name first.

  5. Enable two-factor authentication on financial accounts. If you're not already using it, turn on 2FA for your bank, brokerage, and any account tied to your financial life. Passkeys are even better where your bank supports them, they are phishing-resistant in a way that SMS codes are not.

  6. Consider a data removal service. Your information sits in dozens of data broker databases even before a breach. Services like DeleteMe or Kanary will submit removal requests on your behalf. It reduces your overall exposure for future incidents.

The Deeper Problem No Letter Will Fix

Here's the uncomfortable reality: you had no say in any of this.

You chose your doctor. You did not choose Aesto Health. You did not consent to your SSN being stored on their AWS servers. You did not negotiate their security practices or review their incident response timeline. You found out eight months after the fact because that's how the system works.

Healthcare data flows through layers of vendors, subprocessors, and cloud providers, and patients sit at the end of that chain with no visibility and no leverage. The regulations that govern these vendors exist, but enforcement is slow and fines are rarely proportional to the harm caused.

What protects you most right now isn't a policy change or a lawsuit outcome. It's the concrete steps above, taken today, before the next letter arrives.


Do this now:

  • Freeze your credit (Equifax, Experian, TransUnion), it's free
  • Enroll in Experian IdentityWorks if you received a notification letter
  • Review recent EOBs for unfamiliar medical claims
  • Turn on 2FA or passkeys for financial accounts
  • File your taxes as early as possible this season

Sources

WHAT TO DO RIGHT NOW
  1. 01Go to haveibeenpwned.com and check your email address right now
  2. 02Change your password on the breached service — use a unique password you do not use anywhere else
  3. 03Enable two-factor authentication (2FA) on that account if available
  4. 04Monitor your bank statements and credit report for unusual activity over the next 90 days
RECOMMENDED PROTECTIONAFFILIATE

AuraAll-in-one identity theft and scam protection with real-time alerts

Get Aura
Check Have I Been Pwned →
// FAQ

Common Questions About Breach

What should I do immediately after a data breach?

Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.

Should I freeze my credit after a data breach?

Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

// RELATED

More in breach

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now
2026-09-08T08:03:13.929805+00:00 · 5 min read
Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
2026-09-05T08:04:13.891376+00:00 · 5 min read
Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities
2026-09-03T08:04:32.922878+00:00 · 5 min read

Stay invisible. Follow @hack_decoded