>samit_hota
Back to security news

Security News · SN-2026-434

HIGHOPEN

Aesto Discloses AWS Cloud Breach Exposing 9.5 Million Patient Records

Affected: Aesto · Together Women's Health · Baylor Genetics · CareCloud · Park Dental Partners

Samit Hota·
#news#data-breach#aesto

Federal regulatory filings submitted this week reveal that a December cyberattack against healthcare data archivist Aesto compromised the sensitive personal and medical records of more than 9.5 million individuals. The Birmingham, Alabama-based company officially notified the U.S. Department of Health and Human Services (HHS) of the massive scope following an earlier, preliminary warning sent to impacted clients in June. The Aesto breach highlights the compounding supply-chain risks faced by healthcare providers that rely on specialized third-party aggregators to archive and migrate legacy electronic health records (EHR).

Intrusion Timeline and Data Compromised

According to disclosures made to federal regulators, threat actors gained unauthorized access to Aesto’s Amazon Web Services (AWS) cloud infrastructure between December 2 and December 18. During this 16-day window, attackers exfiltrated massive repositories of sensitive patient records managed on behalf of Aesto’s client base.

The compromised information spans virtually all categories of personally identifiable information (PII) and protected health information (PHI), including:

  • Full patient names and dates of birth
  • Social Security numbers and driver’s license numbers
  • Medical history, diagnostic details, and treatment records
  • Financial account numbers and billing information
  • Health insurance provider details and policy numbers

While Aesto initially notified affected business partners in June that an incident had occurred, the vendor refrained from publishing patient counts or technical specifics until its formal HHS filing this week. At least 30 healthcare organizations were impacted by the security breach. Aesto has begun filing state-level breach notices on behalf of affected customers, including Together Women’s Health for impacted patients across Texas and California. No ransomware group or threat actor has publicly claimed responsibility for the intrusion, and Aesto has not issued further public comment regarding how the initial access was gained.

The Unique Risk Profile of EHR Archiving and Migration

Aesto provides data archiving, extraction, and migration services for medical centers, specialized practices, and health networks undergoing technology upgrades, EHR platform transitions, or corporate acquisitions. When healthcare groups migrate between electronic health record systems or consolidate practices, legacy patient files cannot simply be discarded due to statutory medical record retention mandates.

Instead, organizations routinely outsource legacy database maintenance to third-party archiving firms like Aesto. These specialized vendors extract structured and unstructured records from sunsetted databases, convert them into compliant formats, and store them in centralized cloud repositories.

This operational role creates an extraordinary risk concentration. A single EHR migration vendor often holds decades of legacy medical files aggregated from dozens of independent healthcare providers. For cybercriminals, breaching an archival partner yields a vastly higher return on investment than targeting individual practice management systems one by one. Old patient files stored in archival environments are also less likely to trigger active behavioral monitoring or prompt user query alerts, allowing threat actors to quietly harvest millions of unmonitored entries over extended periods.

Cloud Security Mechanics Behind Data Migration Breaches

While Aesto has not publicly disclosed the exact initial entry vector into its AWS cloud environment, intrusions involving cloud-hosted data pipelines and migration infrastructure typically exploit systemic gaps in identity and access management (IAM) or cloud storage configuration:

  • Stale or Over-Privileged IAM Credentials: Data migration workflows frequently require broad read/write permissions across multiple database instances and Amazon S3 buckets. If long-lived AWS IAM access keys or developer credentials are leaked, hardcoded in deployment scripts, or captured via phishing, attackers gain immediate access to centralized data stores.
  • Inadequate Cloud Storage Access Controls: S3 buckets hosting legacy database backups or unencrypted snapshot files are vulnerable to unauthorized access if bucket policies lack strict IP address restrictions, fail to enforce S3 Block Public Access, or rely on permissive role-based access control (RBAC).
  • Deficient Data Egress and Logging Oversight: Exfiltrating records for 9.5 million patients requires substantial network egress bandwidth. In cloud environments where Amazon GuardDuty or CloudTrail anomaly detection is not configured to flag unusual bulk data reads or S3 GetObject volume spikes, attackers can download entire databases over several weeks without triggering security operations center (SOC) alerts.

Systematic Targeting of Healthcare Data Aggregators

The Aesto data breach represents part of a broader, persistent surge in cyberattacks directed at health tech vendors and data brokers. Just this week, Baylor Genetics notified federal regulators that a June cyber incident exposed the medical testing and laboratory results of over 2.8 million individuals. Electronic health records giant CareCloud disclosed a March incident that compromised data for 3.7 million patients. Meanwhile, healthcare platforms McKesson, Nutex, and Paylogix all reported customer data breaches over the past fortnight, and Park Dental Partners submitted an SEC filing warning of an ongoing incident response engagement following suspected unauthorized access to patient data.

Defensive Controls for Legacy Cloud Data

Organizations managing legacy EHR archives or cloud migration pipelines must enforce stringent posture management on AWS storage assets. Third-party vendor risk management should mandate that external archiving partners provide cryptographic proof of client-side or server-side encryption with customer-managed keys (AWS KMS), ensuring that compromised cloud infrastructure alone does not grant unencrypted access to raw patient data. Additionally, security teams should implement automated GuardDuty threat detection for anomalous CloudTrail S3 data access, enforce short-lived IAM session credentials via AWS STS, and strictly isolate legacy archival databases within Virtual Private Clouds (VPCs) without public internet routing.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call