SecuritySeptember 8, 20268 min read

What to Do After the Aesto Health Data Breach (9.5M Patients)

PT

By PrivacyOn Team

Privacy Research & Removal Operations

SharePostFacebookEmail
What to Do After the Aesto Health Data Breach (9.5M Patients)

Worried you're exposed? Find out in 60 seconds with a free exposure scan.

Aesto Health has notified 9,540,683 people that their data was exposed in a breach of its AWS environment between December 2 and December 18, 2025. Exposed records include Social Security numbers, driver's license numbers, financial account numbers, medical information, and taxpayer IDs. Individual notices began going out on August 21, 2026 — freeze your credit now.

What Happened

Aesto Health, operating as Aesto LLC out of Birmingham, Alabama, is not a hospital or an insurer. It is a behind-the-scenes vendor: it handles secure data migration, electronic health record exchanges, and legacy data archiving for healthcare providers and medical practices. That means it holds historical patient records for organisations you may have visited years ago.

The company detected unauthorised activity in portions of its Amazon Web Services infrastructure on December 18, 2025. A forensic investigation and a manual document review ran for months. On May 26, 2026, Aesto confirmed that an unauthorised actor may have accessed or acquired data between December 2 and December 18, 2025. It began notifying its healthcare-provider clients on June 26, 2026, and started notifying affected individuals on August 21, 2026. The total reported to the US Department of Health and Human Services is 9,540,683 individuals.

Why This One Is Worse Than Most

Most breaches leak an email address and a password. This one leaked the permanent identifiers: Social Security number, driver's license number, date of birth, and financial account numbers, alongside medical records. You cannot change a Social Security number the way you change a password, which is why the response has to be structural — credit freezes and monitoring — rather than just a password reset.

What Data Was Exposed

The exact combination varies by individual, but Aesto has confirmed that the affected data set includes:

  • Full names and dates of birth
  • Social Security numbers
  • Driver's license numbers and other government identification numbers
  • Taxpayer identification numbers
  • Financial account numbers
  • Health insurance information
  • Medical information from archived patient records

Aesto says it has no evidence of identity theft or financial fraud connected to the incident. That is a statement about what has been detected so far, not a guarantee. Data from healthcare vendor breaches routinely surfaces on criminal markets a year or more after the intrusion, which is precisely when the free monitoring offer has expired.

Am I Affected?

You will not necessarily recognise the name Aesto Health, because you were never its customer — your healthcare provider was. If you have received a letter referencing Aesto Health, Aesto LLC, or a records-archiving vendor acting on behalf of a clinic or hospital system, you are in scope.

Because notifications rolled out from August 21, 2026, some letters are still arriving. Do not assume you are clear simply because nothing has landed yet, particularly if you have used a medical practice that changed EHR systems or closed in recent years.

Step 1: Freeze Your Credit at All Three Bureaus

This is the single highest-value action and it is free. A credit freeze blocks new accounts from being opened in your name, which is the main thing a stolen Social Security number is good for. Place one at each bureau separately:

  • Equifax: freeze.equifax.com
  • Experian: experian.com/freeze
  • TransUnion: transunion.com/credit-freeze

Freezing does not affect your credit score and you can lift it temporarily when you apply for credit. Do it for every adult in your household who may have used an affected provider.

Step 2: Enrol in the Monitoring Aesto Is Offering

Aesto is providing complimentary identity theft protection and credit monitoring through Experian. Enrol using the code in your notification letter — there is no reason to leave a free service unused, and enrolling does not waive any legal rights. Note the enrolment deadline printed on the letter; these offers typically expire 60 to 90 days after the notice date.

Be clear-eyed about what it covers. Free post-breach monitoring alerts you after something happens and usually runs for 12 or 24 months. The exposure itself lasts as long as your Social Security number does.

Is your data already out there?

Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.

Run a free scan

★★★★★ 4.8/5 · Trusted by thousands of families

Step 3: Watch for Medical Identity Theft Specifically

Because this breach exposed health insurance details alongside identity data, medical identity theft is a live risk. Someone using your insurance for treatment corrupts your medical record, which can affect future care decisions as well as your finances.

  • Read every Explanation of Benefits from your insurer and query any treatment, provider, or date you do not recognise.
  • Request a copy of your medical records from your main providers and check for entries that are not yours.
  • Ask your insurer for a record of claims paid in your name over the last 12 months.
  • Report suspected medical identity theft to your insurer's fraud line and at identitytheft.gov.

Step 4: Protect the Tax and Financial Angle

Taxpayer identification numbers and financial account numbers were in scope, which opens two additional attack paths:

  • Get an IRS Identity Protection PIN. Request one at irs.gov/ippin. It blocks anyone from filing a tax return in your name without the six-digit code.
  • Set fraud alerts on named accounts. If your letter identifies a specific financial account, call that institution directly using the number on your statement — never a number from an email — and ask for a fraud flag.
  • Turn on transaction alerts for every bank and card account so unusual activity reaches you in minutes rather than at the next statement.

Expect Targeted Phishing and Fake Settlement Emails

Large healthcare breaches are followed within weeks by scams that impersonate the breached company, the monitoring provider, or a class action settlement. Real notifications from Aesto arrive by mail and contain an enrolment code. Never enter a Social Security number into a page you reached from an email link, and never pay a fee to "claim" breach compensation.

Step 5: Reduce the Rest of Your Exposure

A stolen Social Security number is only dangerous when it is paired with the rest of your identity — your current address, phone number, date of birth, relatives, and employer. That supporting data is not on the dark web; it is on data broker and people-search sites, published openly and sold for a few dollars. Fraudsters routinely combine a breached SSN with a broker profile to answer identity verification questions and take over accounts.

PrivacyOn removes your personal information from 100+ data broker and people-search sites, keeps filing when brokers relist you, and includes dark-web monitoring so you know if the Aesto records surface for sale. Plans cover up to five family members from $8.33/month, and the free scan shows your current exposure in about two minutes with no signup.

Do These Three Things Today

1. Freeze your credit at Equifax, Experian, and TransUnion. 2. Enrol in the Experian monitoring using the code in your Aesto letter, before the deadline. 3. Run a free PrivacyOn scan to see which brokers are publishing the address, phone number, and relatives that make a stolen SSN usable — then get that data removed.

The Bottom Line

Nine and a half million people had permanent identifiers exposed by a vendor most of them had never heard of, and the data sat accessible for more than eight months before individual notices went out. The free monitoring is worth taking, but it expires. Credit freezes, an IRS PIN, and shrinking your published data footprint are the parts that keep working after it does.

Frequently Asked Questions

How many people were affected by the Aesto Health data breach?

Aesto Health reported 9,540,683 affected individuals to the US Department of Health and Human Services. The unauthorised access occurred in its AWS environment between December 2 and December 18, 2025, was confirmed on May 26, 2026, and individual notifications began on August 21, 2026.

What information was exposed in the Aesto Health breach?

Depending on the individual, exposed data included full names, dates of birth, Social Security numbers, driver's license numbers, other government identification numbers, taxpayer identification numbers, financial account numbers, health insurance information, and medical information held in archived patient records.

Why did Aesto Health have my medical records if I have never used it?

Aesto Health is a vendor to healthcare providers, not a provider itself. It handles data migration, EHR exchange, and legacy record archiving for clinics and hospital systems. If a practice you visited moved or retired an old records system, your data may have passed through Aesto without you ever hearing the name.

Is the free credit monitoring from Aesto Health enough?

No. It is worth enrolling — it is free and does not affect your legal rights — but it typically runs 12 to 24 months and only alerts you after fraud is attempted. A Social Security number is exposed for life. Credit freezes at all three bureaus, an IRS Identity Protection PIN, and removing your supporting personal data from broker sites do more over the long run.

How do data brokers make a breach like this more dangerous?

A leaked Social Security number is far more usable when paired with your current address, phone number, date of birth, and relatives — exactly the profile data broker and people-search sites publish for anyone to buy. Removing that data from 100+ brokers with a service like PrivacyOn takes away the context fraudsters need to pass identity verification.

What should I do if someone used my health insurance?

Contact your insurer's fraud department immediately, request a full claims history for the past 12 months, and ask your providers for copies of your medical records so you can flag entries that are not yours. Report it at identitytheft.gov, which generates a recovery plan and an official identity theft report you can send to providers and collections agencies.

Can I still act if I have not received a letter?

Yes, and you should. Notifications rolled out from August 21, 2026, and mail goes astray. Credit freezes are free, take about ten minutes per bureau, and are worth placing regardless of which breach reaches you. The same goes for an IRS Identity Protection PIN and a check of your published data broker exposure.

SharePostFacebookEmail
PT
PrivacyOn Team

Privacy Research & Removal Operations

Operates removal across 100+ data broker sitesGuides verified against live opt-out processesContent reviewed and updated continuously

The team that operates PrivacyOn's data-removal service — publishing opt-out guides and privacy research based on handling real removal requests every day.

Find out what's already exposed

A free 60-second scan shows your breaches and broker exposure. PrivacyOn removes it and monitors 24/7 so it stays gone.

★★★★★ 4.8/5 · Trusted by thousands of families