Aesto Health Data Breach Sensitive Personal & Health Information

Published
August 2, 2026
Updated
August 2, 2026
Aesto Health Data Breach Sensitive Personal & Health Information
Aesto Health
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

Birmingham, Alabama based healthcare data management company, Aesto Health, disclosed a data breach that occurred on or about Dec. 18, 2025. As a third-party vendor, Aesto Health manages patient data on behalf of healthcare providers, meaning the breach may have exposed information belonging to patients of those providers.

The incident impacted a limited portion of its Amazon Web Services infrastructure. Upon learning of the issue, the company launched what it described as "a prompt and thorough investigation" with the help of external cybersecurity professionals experienced in handling these types of incidents.

After an extensive forensic investigation and manual document review, Aesto Health confirmed on May 26, 2026, that between on or about Dec. 2 and Dec. 18, 2025, a limited amount of protected health information stored on its network may have been accessed or acquired by an unauthorized actor.

That confirmation came more than five months after the incident was first detected.

The personally identifiable information potentially exposed includes full names, Social Security numbers, drivers' license numbers, state identification numbers and full or partial dates of birth. The protected health information potentially exposed includes health records, medical histories, health insurance policy numbers and claims or billing information.

The breach was reported to the California and Vermont attorneys general on July 31, 2026, with 91 Vermont residents identified as affected. The company also posted a notice of the incident on its website.

Aesto Health's response

Aesto Health notified the affected healthcare provider of the incident on June 26, 2026, according to the company's notification letter. The company then began sending written notification letters to affected individuals. In its notice, the company stated it has "no evidence that any of the information has been misused."

Aesto Health also said, "Please accept our apologies that this incident occurred." The company added that it is "committed to maintaining the privacy of personal information" in its possession and has "taken many precautions to safeguard it." It said it continually evaluates and modifies its practices and internal controls to enhance security and privacy.

Given the sensitive nature of the information involved, Aesto Health is offering affected individuals a complimentary membership to Privacy Solutions ID through Epiq. The length of the membership varies by individual.

The service includes:

  • One-bureau credit monitoring with alerts for key changes such as new accounts and credit inquiries
  • Dark web monitoring for one email address, phone number, name, date of birth and Social Security number
  • Credit security freeze assistance across all three major credit bureaus
  • Change of address monitoring through the National Change of Address database and U.S. Postal Service records
  • Identity restoration and lost wallet assistance from dedicated specialists

Affected individuals can enroll at privacysolutionsid.com using the activation code included in their notification letter. For questions about the enrollment process, individuals can call Epiq directly at 866-675-2006, Monday through Friday from 9 a.m. to 5:30 p.m. Eastern Time.

Aesto Health has also set up a dedicated toll-free response line at 833-918-8060, staffed with individuals familiar with the incident and knowledgeable about steps people can take to protect against misuse of their information. The line is available Monday through Friday from 8 a.m. to 8 p.m. Central Time, excluding major U.S. holidays.

Affected individuals can also contact Aesto LLC by mail at 1800 International Park Drive, Suite 110, Birmingham, AL 35243, or by phone at 866-558-8098.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Aesto Health
Consumers Notification date
Date of Breach
on or about November 5, 2023, and December 6, 2023
Breach Discovered Date
May 14, 2024
Total People Affected
Information Types Exposed
  • Health Records
  • Social Security Numbers
  • claims/billing information including financial and/or Social Security numbers
  • drivers' license numbers
  • full names
  • full or partial dates of birth
  • health insurance policy numbers
  • medical histories
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image