A Healthcare Data Migration Vendor Took Nine Months to Tell 9.5 Million People Its AWS Environment Was Breached
Cybersecurity

A Healthcare Data Migration Vendor Took Nine Months to Tell 9.5 Million People Its AWS Environment Was Breached

Aesto Health's cloud infrastructure was compromised in December 2025, but the Birmingham-based data migration vendor did not finish confirming the scope of the breach until this summer, leaving 9.5 million patients uninformed for the better part of a year.

PublishedSeptember 2, 2026
Read time5 min read
Share

A quiet breach in a business most patients have never heard of

Aesto Health is not a hospital, an insurer, or a brand any consumer would recognize. It is a Birmingham, Alabama-based vendor that provides secure data migration, electronic health record exchange, and legacy data archiving services to healthcare providers and medical practices, the kind of infrastructure company that sits behind the scenes moving patient records between systems during EHR transitions and practice consolidations. That obscurity is precisely why this breach matters more than its low profile suggests.

Hackers compromised Aesto Health's Amazon Web Services infrastructure and exfiltrated data over roughly two weeks, between December 2 and December 18, 2025. The company detected and contained the incident on December 18, which sounds like a reasonably fast response until you look at what happened next. It took until May 26, 2026, more than five months later, for Aesto Health's investigation to determine the actual scope of what had been taken, and until this summer for notification letters to finally reach the healthcare providers and, eventually, the patients whose records had passed through the company's systems.

What was taken and who it belongs to

The scope, once confirmed, was severe. Exposed data includes names, Social Security numbers, driver's license numbers and other identification numbers, dates of birth, financial account numbers, medical information, health insurance information, and taxpayer identification numbers, a combination that gives an attacker nearly everything needed for identity theft, medical fraud, and financial fraud simultaneously. The Department of Health and Human Services added Aesto Health to its breach portal on September 1, 2026, formally confirming 9,540,683 individuals were affected.

Those 9.5 million people are patients of at least two dozen healthcare provider clients spread across multiple states, meaning almost none of them had a direct relationship with Aesto Health at all, or any way to know their records had ever passed through its systems in the first place. Most likely learned their data was migrated by a third party for the first time in the same letter that told them it had been stolen. In its statement, the company said: 'Upon detecting the unauthorized activity, we immediately contained the incident and commenced a thorough investigation. As part of our investigation, we engaged leading cybersecurity experts to identify what personal information, if any, was involved.'

The nine month gap is the actual failure

Containing an incident within two weeks is a defensible outcome. Taking five additional months to determine what was actually stolen, and longer still to notify the individuals affected, points to a much more common and much less discussed failure mode: organizations that can detect an intrusion but cannot quickly and confidently answer the question that matters most, exactly what left the building. That gap between containment and scoping is where breach costs, regulatory exposure, and reputational damage compound.

For a company whose entire business model is handling other organizations' patient data during migrations and system transitions, the ability to answer that question quickly should be table stakes, not an aspiration. Data migration work inherently involves large volumes of records moving through temporary storage and processing pipelines, exactly the kind of environment where logging, access controls, and data lineage tracking need to be built in from day one rather than reconstructed forensically after the fact.

Why this is a vendor risk story, not just a breach story

None of the healthcare providers whose patients were exposed chose to have their data compromised, they chose a vendor to help with a system migration, and that vendor's AWS environment turned out to be the weak point. This is the recurring shape of enterprise data breaches in 2026: the direct victim organization often has a mature security program, and the actual failure sits one or two layers down the vendor chain, in a company whose core competency is data handling but whose security investment did not keep pace with the sensitivity of what it processes.

For any CTO or CIO overseeing vendor risk in a regulated data environment, healthcare, financial services, or otherwise, the operative question after an incident like this is not whether your direct vendors have a security certification on file. It is whether your due diligence process actually tests a vendor's ability to detect and scope a breach quickly, since that capability, not the presence of a policy document, is what determined the nine month gap here.

What this means for vendor governance going forward

If your organization works with data migration, EHR exchange, or archiving vendors of any kind, this incident is worth a direct conversation with each one this quarter rather than a note filed away for the next renewal cycle. Ask specifically how they would detect exfiltration from their own cloud infrastructure, how long historical scoping realistically takes given their current logging and data lineage setup, and what contractual notification timeline they are actually bound to versus the roughly nine months it took here, then compare that answer to what your own contract actually specifies in writing.

The broader lesson applies well past healthcare. Any vendor that touches sensitive data as a core part of its service, rather than as an incidental byproduct of some other function, deserves security diligence proportional to that role, including contractual breach notification timelines with real financial teeth behind them. Nine months from exfiltration to public disclosure has become a predictable outcome of treating vendor security as a checkbox exercise during procurement instead of an operational capability that gets tested and verified on a recurring basis long after the contract is signed.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#healthcare-security#data-breach#vendor-risk#aesto-health#aws-security#hipaa