The US Department of Health and Human Services lists 9,540,683 people as affected by a hacking incident reported by healthcare data-migration and archiving provider Aesto Health. Aesto says the incident affected a limited portion of its Amazon Web Services infrastructure and involved protected health information belonging to patients of multiple healthcare clients.
The number is official, but the public wording still matters. Aesto says information may have been accessed and/or acquired by an unauthorized actor. Its notice does not identify the initial-access method, attribute the incident to a named actor or establish that every listed data element was exposed for every affected person.
What Aesto and HHS have confirmed
Aesto detected unauthorized activity on December 18, 2025. After forensic investigation and a manual review of documents, the company says it confirmed on May 26, 2026 that certain information may have been accessed or acquired between approximately December 2 and December 18. It began notifying affected healthcare clients on June 26.
The HHS Office for Civil Rights breach portal records Aesto as a business associate, lists 9,540,683 individuals and classifies the event as a hacking or IT incident involving a network server. The record was submitted on July 31, 2026. That portal entry establishes the reported scale; it does not answer how the actor entered the environment or which safeguards failed.
According to Aesto, the potentially involved fields varied by person and could include:
- names and dates of birth;
- medical and health-insurance information;
- driver's licence and other government identification numbers;
- financial-account and taxpayer-identification numbers; and
- Social Security numbers for a limited number of people.
Aesto said it had no evidence of identity theft or financial fraud connected to the incident when it issued the notice. That is not a guarantee that misuse cannot occur later, and it should not be read as proof that the affected files were harmless.
Legacy archives turn one vendor into a concentration point
Aesto's role is the central lesson. Data-migration and archiving providers can hold records from many healthcare organizations, including information copied out of systems that are no longer in daily use. A compromise at one business associate can therefore cross organizational boundaries without compromising every hospital or practice separately.
Healthcare organizations cannot simply delete records that law, patient care or continuity obligations require them to retain. Data minimization is more precise than indiscriminate deletion: keep the authoritative record for the required period, while removing avoidable exports, temporary migration packages, decrypted working copies, support attachments and duplicate vendor archives.
The same distinction applies to secrets. An organization may need to preserve evidence that an administrator approved a migration, but it rarely needs the database password, API token, decryption key or recovery code copied into the ticket that documented the work.
A safer workflow for healthcare migrations and archives
- Map every copy before the move. Record the data owner, system, purpose, legal retention period, vendor and deletion trigger.
- Extract only required fields. Do not move an entire historical schema when the receiving archive needs a narrower clinical or regulatory record.
- Encrypt the package and separate the key. The file and the value that decrypts it should not travel through the same persistent inbox, ticket or chat.
- Expire temporary access. Migration accounts, download links and staging buckets should have short, documented lifetimes rather than becoming permanent infrastructure.
- Remove working copies. Confirm deletion from staging systems, operator endpoints, support tools and vendor workspaces after validation.
- Limit vendor identities. Use named accounts, least privilege, phishing-resistant authentication and explicit approval for bulk exports.
- Log custody without logging content. Preserve who shared what category of material, with whom and when, without recording the secret or sensitive payload itself.
- Test the exit clause. Contracts should define return, deletion evidence, incident notification and access revocation when the migration or vendor relationship ends.
Where Secretus can help
Secretus can deliver a temporary password, decryption value, recovery code or encrypted file through a one-time link instead of leaving the payload in a long-lived collaboration archive. Short expiry narrows the delivery window, while the ticket can retain the operational context and approval evidence without retaining the secret itself.
Secretus is not a medical-record archive and does not secure an already compromised browser, endpoint, cloud account or vendor environment. It addresses the human handoff between verified participants. Endpoint trust, encryption at rest, identity controls, retention enforcement and vendor oversight still have to protect the systems on both sides of that handoff.
What remains unknown
Public sources do not identify the initial-access vector, the actor, the exact number of affected healthcare clients or whether all accessed information was exfiltrated. They do not establish that AWS itself was compromised; Aesto describes activity within part of its AWS-hosted infrastructure. Organizations should avoid filling those gaps with an assumed phishing, credential-theft or cloud-configuration narrative.
