{
  "id": 5151058,
  "title": "More than 9.5 million patient records affected by Aesto Health data breach: what you need to know",
  "url": "https://urgent.news/2026/09/02/more-than-9-5-million-patient-records-affected-by-aesto-health-data",
  "topic": "health",
  "section": "Health & Medicine",
  "published": "2026-09-02T18:58:26.000Z",
  "source": {
    "name": "Tom's Guide",
    "slug": "tom-s-guide",
    "url": "https://www.tomsguide.com/computing/online-security/more-than-9-5-million-patient-records-affected-by-aesto-health-data-breach-what-you-need-to-know"
  },
  "original_language": "en",
  "account": "Aesto Health disclosed a massive data breach affecting over 9.5 million individuals. The software company supplies healthcare organizations with tools to manage patient data during records system transitions. Initially noticed by Bleeping Computer on June 24, the breach itself took place in December 2025 and remained undetected until May 26 of this year. According to the notice, unauthorized access occurred via Aesto's Amazon Web Services infrastructure between December 2 and December 18, 2025.\n\nThe compromised data included sensitive information such as full names, dates of birth, medical history, driver's license numbers, financial account details, health insurance information, taxpayer ID numbers, Social Security numbers, and other government-issued IDs. Healthcare organizations implicated in the breach span 29 entities, including Edwards County Medical Center, Marana Health, My Doctor, LLC, the Nebraska Orthopedic Center, and Women's Health Associates.\n\nAesto began notifying affected individuals on August 21, offering identity theft protection and credit monitoring through Experian. Following this incident, which joins a string of breaches impacting healthcare companies like CareCloud, Nutex Health, iRhythm, and McKesson, no threat group has publicly claimed responsibility for the attack, unlike other recent breaches linked to ShinyHunters.\n\nTo safeguard yourself post-breach, review the full list of affected organizations on the HIPAA Journal. If you've used any healthcare provider, you may receive a notification letter from Aesto. Utilize the provided Experian coverage and monitor your mailbox for such letters. Even without a formal letter, consider investing in a reputable identity theft protection service to shield your personal information. With the rise of cyber threats, healthcare companies must prioritize enhancing their cybersecurity measures.",
  "summary": "Aesto Health has confirmed a data breach that affects more than 9.5 million patients.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "TechRadar",
        "title": "More than 9.5 million patients affected by Aesto Health breach — names, SSNs, financial details, health records and more stolen",
        "url": "https://urgent.news/2026/09/02/more-than-9-5-million-patients-affected-by-aesto-health-breach-names",
        "published": "2026-09-02T12:35:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}