
Birmingham, Alabama based healthcare data management company, Aesto Health, disclosed a data breach that occurred on or about Dec. 18, 2025. As a third-party vendor, Aesto Health manages patient data on behalf of healthcare providers, meaning the breach may have exposed information belonging to patients of those providers.
The incident impacted a limited portion of its Amazon Web Services infrastructure. Upon learning of the issue, the company launched what it described as "a prompt and thorough investigation" with the help of external cybersecurity professionals experienced in handling these types of incidents.
After an extensive forensic investigation and manual document review, Aesto Health confirmed on May 26, 2026, that between on or about Dec. 2 and Dec. 18, 2025, a limited amount of protected health information stored on its network may have been accessed or acquired by an unauthorized actor.
That confirmation came more than five months after the incident was first detected.
The personally identifiable information potentially exposed includes full names, Social Security numbers, drivers' license numbers, state identification numbers and full or partial dates of birth. The protected health information potentially exposed includes health records, medical histories, health insurance policy numbers and claims or billing information.
The breach was reported to the California and Vermont attorneys general on July 31, 2026, with 91 Vermont residents identified as affected. The company also posted a notice of the incident on its website.
Aesto Health notified the affected healthcare provider of the incident on June 26, 2026, according to the company's notification letter. The company then began sending written notification letters to affected individuals. In its notice, the company stated it has "no evidence that any of the information has been misused."
Aesto Health also said, "Please accept our apologies that this incident occurred." The company added that it is "committed to maintaining the privacy of personal information" in its possession and has "taken many precautions to safeguard it." It said it continually evaluates and modifies its practices and internal controls to enhance security and privacy.
Given the sensitive nature of the information involved, Aesto Health is offering affected individuals a complimentary membership to Privacy Solutions ID through Epiq. The length of the membership varies by individual.
The service includes:
Affected individuals can enroll at privacysolutionsid.com using the activation code included in their notification letter. For questions about the enrollment process, individuals can call Epiq directly at 866-675-2006, Monday through Friday from 9 a.m. to 5:30 p.m. Eastern Time.
Aesto Health has also set up a dedicated toll-free response line at 833-918-8060, staffed with individuals familiar with the incident and knowledgeable about steps people can take to protect against misuse of their information. The line is available Monday through Friday from 8 a.m. to 8 p.m. Central Time, excluding major U.S. holidays.
Affected individuals can also contact Aesto LLC by mail at 1800 International Park Drive, Suite 110, Birmingham, AL 35243, or by phone at 866-558-8098.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)