Alabama health data vendor breach reaches two dozen provider clients

An AWS intrusion at Alabama health data vendor Aesto Health has rippled across two dozen provider clients and hundreds of thousands of patients.

MedRisk Staff
By
2 Min Read

A data breach at Aesto Health, a Birmingham, Alabama company that handles EHR data migration, legacy archiving, and record exchanges for medical practices, has rippled across more than two dozen healthcare provider clients. Aesto said an intruder held access to part of its Amazon Web Services environment between December 2 and December 18, 2025, and that the files involved held personally identifiable information and protected health information.

The affected data categories include full names, Social Security numbers, partial dates of birth, driver’s license and state ID numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims and billing information, and health insurance details. Client notifications started going out June 26, 2026.

State attorney general listings show at least 80,622 South Carolina residents, 37,253 Washington residents, 731 Oregon residents, and 91 Vermont residents affected, with several clients reporting the breach themselves. Village Practice Management confirmed more than 25,000 of its patients were impacted, and Everside Health told the Washington attorney general that roughly 22,000 individuals were affected in that state alone. The full patient count is likely in the hundreds of thousands.

The incident underscores the business associate exposure chain: covered entities remain responsible for meeting HIPAA breach notification requirements even when a vendor holds the data. Health systems should confirm whether any of their vendors rely on Aesto for archive or migration services, review their own notification obligations, and ask vendors for evidence of forensic findings rather than waiting for letters.

Share This Article