Aesto

Aug 2026 · Graded Verified · Healthcare and Life Sciences · Government record
AestoAug 2026
Aesto Health's AWS infrastructure was breached, exposing the PII and PHI of 9,540,683 people across up to 29 provider clients, from VillageMD to Monroe Health Center. The filing names no entry point and no actor, only the aggregate count. Aesto was hired to migrate and archive records; instead, it became the single failure domain for dozens of practices that never touched its cloud. One vendor's infrastructure was the perimeter for an entire health system's worth of patients.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life Sciences
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.
← The complete On the Government Record ledger ← Back to the index