A data breach at Aesto Health, a Birmingham, Alabama-based healthcare technology company, has affected several of its healthcare provider clients. Aesto Health provides secure data migration, legacy data archiving, and electronic health record (EHR) exchanges for medical practices and healthcare enterprises. According to its announcement, a security incident was identified on or around December 18, 2025, involving part of its Amazon Web Services (AWS) infrastructure.
Third-party cybersecurity experts were engaged to investigate the incident and confirmed that its AWS environment was accessed by an unauthorized third party between December 2 and December 18, 2025. The affected parts of its infrastructure were reviewed and confirmed to contain personally identifiable information and protected health information, including full names, Social Security numbers, partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information.
Aesto Health said it had taken many precautions to safeguard the sensitive data in its possession and continually evaluates and modifies its security practices. Credit monitoring and identity theft protection services have been made available. The incident is known to have affected more than two dozen of its healthcare provider clients.
They started to be notified on June 26, 2026. Whenever there is a data breach at a business associate of a HIPAA-covered entity, the affected covered entity is ultimately responsible for ensuring that the requirements of the HIPAA Breach Notification Rule are met. The covered entity may delegate the responsibility for issuing notification letters to the breached business associate, or it may choose to issue notification letters itself.
As a result, it is often difficult to determine how many individuals have been affected by a business associate data breach, although in this case the breach has certainly affected hundreds of thousands of patients. Based on state Attorney General breach listings, at least 80,622 South Carolina residents, 37,253 Washington residents, 731 Oregon residents, and 91 Vermont residents have been affected; however, many of the affected clients have chosen to report the breach themselves.
In some cases, clients report that tens of thousands of their patients have been affected. For instance, Village Practice Management has confirmed that more than 25,000 of its patients have been affected, and Everside Health informed the Washington Attorney General that approximately 22,000 individuals have been affected in Washington alone. Get The FREE HIPAA Compliance Checklist Immediate Delivery of Checklist Link To Your Email Address Please enable JavaScript in your browser to complete this form.
Business Email * Name * First Last Number * Company Name * Get Free Checklist Please Enter Correct Email Address Your Privacy Respected HIPAA Journal Privacy Policy The healthcare providers known to have been affected are detailed in the table below, although others may also have been affected. Edwards County Medical Center Effingham Obstetrics & Gynecology Associates, PLLC Ellenville Regional Hospital Everside Health Gila Health Resources, LLC Graham County Hospital Greenwood County Hospital Henry County Hospital Little River Memorial Hospital Main Street Medical Services, PLLC Marana Health Mid-South OB-GYN, PLLC Midtown Community Health Center Missoula Community Health Services Inc.
, dba Mineral Community Hospital Monroe Health Center My Doctor, LLC Nebraska Orthopedic Center, P. C Park West Health Systems, Inc. Quincy Valley Medical Center Rural Health Resources of Jackson County Inc.
d/b/a Holton Community Hospital Shenandoah Valley Medical System Inc. Sterling Health Solutions Texas Spine Consultants, LLP Together Women’s Health Medical Group of Alabama, PC Together Women’s Health Medical Group, PC Village Practice Management (VillageMD; Village Medical) Women’s Health Associates, Inc. The post Aesto Health Data Security Incident Affects Multiple Healthcare Provider Clients appeared first on The HIPAA Journal .
Originally published at hipaajournal.com


