Cases & Investigations
Aesto Health Data Breach Investigation
Type: Investigations
Defendant(s): Aesto Health
Wolf Popper LLP is investigating potential legal claims on behalf of individuals whose personal and health information may have been exposed in a data breach affecting Aesto Health.
Aesto Health, a Birmingham, Alabama-based healthcare technology company, provides data migration, electronic health record (EHR) exchange, and legacy data archiving services to healthcare providers and medical practices. According to Aesto Health, the company discovered unauthorized activity involving portions of its Amazon Web Services (AWS) infrastructure on December 18, 2025.
Aesto Health determined on May 26, 2026, that an unauthorized person may have accessed or acquired personal and protected health information between December 2, 2025, and December 18, 2025. According to information reported to the U.S. Department of Health and Human Services (HHS), the data breach affected approximately 9.5 million individuals.
The information potentially exposed in the data breach varies from person to person but may include names, Social Security numbers, driver’s license numbers, other government-issued identification numbers, dates of birth, financial account information, taxpayer identification numbers, medical information, health insurance information, medical records, medical histories, and claims or billing information.
Aesto Health provides services to healthcare providers and medical practices, meaning the affected information may belong to patients of those providers. At least two dozen healthcare provider clients have reportedly been affected by the data breach.
When personal and health information is exposed, it can put individuals at risk of identity theft, financial fraud, and medical identity theft. Even if your information has not been misused, it is important to remain alert for suspicious activity.
Wolf Popper is investigating whether Aesto Health took reasonable steps to protect the sensitive personal and health information it collected, stored, and managed on behalf of healthcare providers. If Aesto Health failed to use reasonable safeguards to protect that information, individuals affected by the data breach may have legal claims.
If you received a letter from Aesto Health or another healthcare provider notifying you that your information may have been affected by the Aesto Health data breach, Wolf Popper would like to hear from you. Contact us for a free and confidential review of your situation by one of our attorneys to learn more about your legal rights and whether you may have a claim.
Aesto Health, a Birmingham, Alabama-based healthcare technology company, provides data migration, electronic health record (EHR) exchange, and legacy data archiving services to healthcare providers and medical practices. According to Aesto Health, the company discovered unauthorized activity involving portions of its Amazon Web Services (AWS) infrastructure on December 18, 2025.
Aesto Health determined on May 26, 2026, that an unauthorized person may have accessed or acquired personal and protected health information between December 2, 2025, and December 18, 2025. According to information reported to the U.S. Department of Health and Human Services (HHS), the data breach affected approximately 9.5 million individuals.
The information potentially exposed in the data breach varies from person to person but may include names, Social Security numbers, driver’s license numbers, other government-issued identification numbers, dates of birth, financial account information, taxpayer identification numbers, medical information, health insurance information, medical records, medical histories, and claims or billing information.
Aesto Health provides services to healthcare providers and medical practices, meaning the affected information may belong to patients of those providers. At least two dozen healthcare provider clients have reportedly been affected by the data breach.
When personal and health information is exposed, it can put individuals at risk of identity theft, financial fraud, and medical identity theft. Even if your information has not been misused, it is important to remain alert for suspicious activity.
Wolf Popper is investigating whether Aesto Health took reasonable steps to protect the sensitive personal and health information it collected, stored, and managed on behalf of healthcare providers. If Aesto Health failed to use reasonable safeguards to protect that information, individuals affected by the data breach may have legal claims.
If you received a letter from Aesto Health or another healthcare provider notifying you that your information may have been affected by the Aesto Health data breach, Wolf Popper would like to hear from you. Contact us for a free and confidential review of your situation by one of our attorneys to learn more about your legal rights and whether you may have a claim.
Contact Instructions