Aesto, LLC, a healthcare data migration and service provider, confirmed a data security incident on May 26, 2026. This incident involved unauthorized access or acquisition of data stored in its AWS environment, potentially occurring between December 2, 2025, and December 18, 2025, with the network security incident identified on or about December 18, 2025. Aesto began notifying its covered-entity clients on June 26, 2026.
The exposed data may include full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, and other government identification numbers. Social Security numbers were potentially involved for a limited number of individuals. One state AG disclosure record lists 1 affected individual, although this appears to be an incomplete count for the broader incident. The full scope of affected individuals remains unclear.
Details can emerge later, and notices to individuals may be delayed. A Massachusetts State AG filing with a first filing date of July 1, 2026, has been made.