2 SEP 2026 — Aesto Health has begun notifying 9,540,683 people about an intrusion that ran from 2 to 18 December 2025. The company confirmed it internally on 26 May 2026 and started notifying individuals on 21 August. HIPAA's 60-day clock runs from discovery, so a five-month gap before discovering costs nothing under the rule.

The dates, in order

The unauthorised access occurred between 2 and 18 December 2025, in what the company describes as a limited portion of its Amazon Web Services infrastructure. Internal confirmation came on 26 May 2026. A notice went up on the company website on 24 June 2026. Individual notifications began on 21 August 2026.

The timeline runs to five and a half months from intrusion to confirmation, and another three months before letters reached people. All told, eight months passed between the breach and the first notifications.

Aesto Health provides software that lets healthcare organisations migrate, archive and access patient data during electronic health record transitions and practice acquisitions. Twenty-nine providers are affected, including VillageMD, Everside Health, Marana Health and Together Women's Health.

9,540,683Individuals being notified
2–18 Dec 2025The intrusion window
26 May 2026When the company confirmed it internally
21 Aug 2026When individual notifications began — eight months after the intrusion

The rule has no duty to discover

The HIPAA breach notification rule requires notification without unreasonable delay and no later than 60 days from discovery. Every deadline in it is anchored to discovery.

Discovery is the first day a breach is known, or would have been known by exercising reasonable diligence. The rule's only pressure on detection comes from that last clause, which a regulator might assess after the fact.

An organisation that takes five months to establish what happened has not breached the timetable. It has simply started its 60-day clock five months late. Everything after that point can be compliant, while the people affected spent that time unaware their Social Security numbers were in other hands.

What was taken makes the delay expensive

The categories reported are names, dates of birth, medical information, driver's licence numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, government identification numbers and Social Security numbers.

That combination is a complete identity package. A name with a date of birth and a Social Security number is enough to open credit; add a driver's licence number and government identification and it supports account takeover at institutions that verify by knowledge rather than by document.

None of those identifiers can be changed on request. A password compromised in December and disclosed in August costs the user a password reset. A Social Security number compromised on the same timeline has been available to an attacker for eight months and stays compromised for good.

Why five months is plausible rather than negligent

A gap that long suggests someone sat on the news. The more likely explanation is duller and harder to fix.

Establishing what left a cloud environment during a two-week window five months earlier is an exercise in log retention. Default retention for cloud storage access logs and API audit trails is frequently 90 days, and beyond that an investigator is reconstructing from whatever was exported to longer-term storage — usually not everything, and rarely at the object level. Producing a defensible list of 9.5 million affected individuals from partial evidence takes months, and most of that work is proving what was not touched.

This is not an excuse. It points to the control that would have shortened the timeline: log retention. Keeping logs long enough to investigate last quarter costs little, and it is the difference between a five-month investigation and a five-week one. It is also the line most often cut when someone reviews a cloud bill.

This is the business-associate pattern again

Aesto is not a hospital. It is a vendor holding patient data on behalf of 29 provider organisations during system migrations, which is to say it is a business associate under HIPAA and its customers are the covered entities.

The concentration risk is inherent to the product. A company that moves records between electronic health record systems holds complete historical datasets for every practice it serves. That is how a single vendor ends up with 9.5 million records, a number far larger than any of its individual customers hold.

We reported yesterday that a business associate notifies the practices and each practice notifies its own patients. The same structure is here, and this incident shows the other end of it: eight months later, the letters are arriving from a company most recipients have never heard of, about data their own doctor handed over during a software change.

What to do if a letter arrives

The offer is 24 months of identity theft protection and credit monitoring through Experian. Take it, and understand what it does — it watches for new accounts and alerts you afterwards. It does not prevent anything.

A credit freeze does prevent new accounts from being opened, it is free in the United States, and it has to be placed separately with each of the three bureaus. For data of this age, a freeze is the measure that matches the exposure, because the window in which this information gets used has already been open for eight months and monitoring only tells you when it happens.

For organisations, the transferable question is about vendors rather than about this company. A supplier that holds your archived patient data during a migration should have a contractual obligation to notify you within a defined period of detecting anything anomalous, not within a period that starts once they have finished deciding what happened. That clause is negotiable and is rarely negotiated.