Aesto Health, a Birmingham, Alabama-based healthcare data migration and records-exchange vendor, disclosed that a network intrusion between December 2 and December 18, 2025 exposed the protected health information of patients across more than two dozen healthcare provider clients. The company’s own notice says it “immediately contained the incident and commenced a thorough investigation” after confirming the breach on May 26, 2026, and began notifying affected clients on June 26. Exposed data includes full names, dates of birth, Social Security numbers, driver’s license numbers, financial account numbers, health insurance information, and medical records.
The nearly six-month gap between the intrusion and confirmation, and the further month before client notification began, is the part that matters most for the security leader, not the record count alone. Aesto sits behind its healthcare-provider clients as a data-processing vendor rather than a patient-facing brand, which means the providers whose patients are actually affected had no direct visibility into their own exposure until a third party told them. “The privacy and security of the personal information we maintain is of the utmost importance to Aesto,” the company said in its notice, a statement that reads very differently against a six-month detection-to-disclosure window.
The original insight: this is now a recurring shape of breach, a vendor holding data on behalf of many downstream healthcare organizations, rather than a single hospital system being hit directly, a pattern also visible in CyberTech’s recent coverage of a healthcare extortion incident and in a single vendor breach cascading across a dozen state court systems. Any organization outsourcing records migration, archiving, or EHR exchange to a third party should confirm that vendor’s own breach-notification SLA and detection tooling now, rather than assuming a downstream vendor incident will surface on a timeline the organization controls.
Source: Aesto Health