Skip to main content
174 Days to Confirm a Healthcare BreachBreach & Risk Assessment
5 min readFor Legal and Compliance Teams

174 Days to Confirm a Healthcare Breach

The Challenge

Between December 2 and December 18, 2025, an unauthorized actor accessed Amazon Web Services infrastructure belonging to Aesto Health, a healthcare data management provider. Aesto stores protected health information for healthcare organizations migrating between electronic health record systems or integrating data from acquired medical practices.

The breach went undetected until May 26, 2026, when forensic investigators confirmed it after an extensive investigation. That's 174 days from initial access to confirmation. By the time Aesto notified affected individuals on August 21, eight months had passed since the breach began.

The compromised data included names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance details, taxpayer identification numbers, other government IDs, and Social Security numbers. The scope: 9,540,683 individuals across 29 healthcare providers, including VillageMD, Everside Health, Marana Health, and Together Women's Health.

The Environment and Constraints

Aesto operates as a business associate under HIPAA, providing software-as-a-service solutions that handle sensitive healthcare data. When a hospital switches EHR platforms or acquires another practice, Aesto's systems archive years of protected health information.

This creates a concentrated risk. A breach at Aesto affects dozens of entities. The 29 impacted healthcare providers shared exposure through a common vendor relationship.

The infrastructure ran on Amazon Web Services, introducing a shared responsibility model. AWS secures the cloud infrastructure; Aesto secures what runs on it. This boundary is crucial during forensic investigations, requiring coordination across multiple technical layers with different logging capabilities and access controls.

The timing in December compounded detection challenges. Holiday periods often see reduced security staffing and delayed incident escalation. Attackers know this. The 16-day window suggests either persistent access or multiple intrusion attempts during a period of potentially less rigorous monitoring.

The Approach Taken

Aesto engaged external forensic specialists to investigate the intrusion. This decision aligns with standard practice for healthcare breaches: bring in third-party experts who can provide independent findings and testify to the investigation's thoroughness if litigation follows.

The investigation included manual document review, highlighting the breach's complexity. Automated log analysis wasn't enough to determine what data the attacker accessed. Investigators had to examine individual files to confirm exposure, a labor-intensive process that extends timelines but ensures defensible findings.

On May 26, 2026, Aesto confirmed internally that protected health information had been accessed. The company disclosed the incident publicly on June 24 via a website notification, then began individual notifications on August 21. This sequence suggests the two-month gap between internal confirmation and individual notification was spent identifying affected individuals across 29 different covered entities.

Aesto offered 24 months of identity theft protection and credit monitoring through Experian to all affected individuals. This exceeds the typical 12-month offering and reflects the sensitivity of the compromised data types.

Results and Metrics

The breach notification to the U.S. Department of Health and Human Services listed 9,540,683 affected individuals, making this one of the larger healthcare breaches in recent years. The indirect impact on 29 healthcare providers demonstrates how business associate breaches multiply compliance obligations: each covered entity must now assess whether its own notification obligations have been triggered and evaluate the business associate relationship.

The 174-day detection gap raises HIPAA compliance questions. The HIPAA Breach Notification Rule requires notification to affected individuals "without unreasonable delay and in no case later than 60 calendar days" after discovery of the breach. Aesto's timeline from internal confirmation (May 26) to individual notification (August 21) is 87 days, exceeding the 60-day window. The company would need to document what made the delay reasonable, likely pointing to the complexity of identifying affected individuals across multiple covered entities.

No threat groups publicly claimed the attack, which is increasingly common in healthcare breaches. Attackers targeting protected health information often operate quietly, monetizing stolen credentials and medical records through private channels.

What They Would Do Differently

The timeline reveals areas for improvement.

First: detection capabilities. A five-month gap between intrusion and discovery indicates monitoring didn't flag the initial access, lateral movement, or data exfiltration. Healthcare business associates handling protected health information need real-time alerting on anomalous AWS API calls, unusual data access patterns, and credential misuse.

Second: investigation speed. The period between discovery and internal confirmation consumed additional months. While manual document review was necessary, the investigation should support faster preliminary findings. You can't compress forensic rigor, but you can parallelize workstreams: one team confirms the breach occurred while another begins identifying affected individuals.

Third: vendor communication protocols. The 29 covered entities learned about the breach through Aesto's investigation, not through their own monitoring. Business associate agreements should specify detection and notification SLAs, not just general security commitments. When you're storing another organization's protected health information, delayed notification creates cascading compliance failures.

Takeaways for Your Team

If you're a covered entity relying on business associates for data migration, archiving, or legacy system access, this breach exposes three control gaps:

Verify monitoring coverage in your business associate agreements. The standard BAA language requires "appropriate safeguards" but doesn't specify detection capabilities. Add explicit requirements: security information and event management systems, anomaly detection on data access, and maximum time-to-detection SLAs. Then audit them. Your business associate's security posture is your security posture.

Map your data across business associate relationships. Aesto stored historical patient records that covered entities might not actively track. You need an inventory of what protected health information sits with which vendors, how long it's retained, and whether you still need it. If you acquired a practice five years ago and migrated the EHR data, do you still need the business associate maintaining the archive?

Build breach notification playbooks that account for vendor incidents. When your business associate confirms a breach, your 60-day notification clock starts ticking, but you're dependent on their investigation to identify your affected individuals. Negotiate data-sharing protocols in advance: what information will they provide, in what format, and how quickly? The covered entities impacted by Aesto's breach couldn't start their own notification processes until Aesto completed its investigation.

If you're a business associate providing healthcare data services, the regulatory implications are direct. HIPAA's Breach Notification Rule applies to you. The 60-day notification requirement runs from your discovery of the breach, not from when you finish your investigation. You can't pause the clock for forensic analysis. This creates tension between thorough investigation and timely notification, but the regulation resolves it clearly: notify based on what you know, then update as you learn more.

The Aesto breach is the latest in a series affecting healthcare technology vendors, including iRhythm, Xolis, Medronic, MCBS, Unlimited Technology Systems, CareCloud, Nutex Health, and McKesson. The pattern is consistent: attackers target business associates because they aggregate protected health information across multiple covered entities. One successful intrusion yields millions of records.

Your detection capabilities need to match that threat model. 174 days is unacceptable.

You Might Also Like