The Records You Stopped Using Are Still Yours to Lose
On Monday, a company in Birmingham, Alabama, that most hospital boards have never heard of reported a breach of 9,540,683 patient records to the Department of Health and Human Services. Aesto Health is now, by HIPAA Journal's count, the second-largest confirmed healthcare data breach of 2026, behind only DentaQuest.
Aesto is not a hospital. It does not treat anyone. What it does is take the patient records a provider no longer actively uses — the archive from the old electronic health record system, the files from a practice you acquired — and hold them for you. Data migration, legacy archiving, record exchange. It is the healthcare equivalent of the storage unit across town.
Somebody got into the storage unit.
Eight Months From the First Sign to the First Number
I have sat in enough breach war rooms to know that the timeline is where boards get surprised, so I will lay this one out plainly.
Aesto says an unauthorized party was inside part of its Amazon Web Services environment from on or about December 2 through December 18, 2025. The company detected the activity on December 18 and, by its own account, contained it immediately and brought in outside forensics.
It took until May 26, 2026 — five months — for that investigation to confirm that protected health information had actually been accessed or taken. Aesto posted a notice on its website in late June and began notifying its healthcare provider clients on June 26. Individual patient letters started going out August 21. The HHS breach portal listing, with the 9.5 million figure attached, arrived on August 31.
Nothing in that sequence is unusual. That is the problem. Eight months from detection to a public headcount is roughly what a competent, well-lawyered response to a cloud data theft looks like in 2026. If your board expects to know the size of a third-party breach in a week, or a month, you have the wrong mental model.
The Names on the Notification Letters Are Not Aesto's
Here is the part I want every director to sit with.
Under HIPAA, Aesto is a "business associate." The hospitals and practices that hired it are "covered entities." When a business associate is breached, the covered entity is the one ultimately responsible for making sure patients are notified. Aesto can be delegated the job. The liability does not move.
HIPAA Journal has identified at least 30 affected providers so far. Read the list. Graham County Hospital. Little River Memorial Hospital. Holton Community Hospital in rural Kansas. Ellenville Regional Hospital in upstate New York. Everside Health, which told the Washington state attorney general that roughly 22,000 of its patients were affected in that state alone. Village Practice Management — VillageMD — with more than 25,000.
Many of those are small, rural, or community hospitals. The kind that outsource legacy archiving precisely because they do not have the staff to run a second EHR in a back room. They made a reasonable operational decision, and the consequence of that decision is now a notification letter with their name on the letterhead, going to patients who may not have set foot in the building in years.
In my experience, this is the single most common blind spot in third-party risk programs. Vendor risk reviews are organized around vendors you are actively using. Nobody schedules an annual review of the company holding the records from the system you retired in 2019.
What the Business Associate Agreement Did Not Do
Every one of those 30 providers had a business associate agreement with Aesto. HIPAA requires it. The BAA spells out permitted uses, security obligations, breach notification duties. It is a compliance document, and it was almost certainly in order.
It did not stop the breach. It did not shorten the eight months. It did not move the notification obligation off the hospital's desk.
I have spent a lot of pages in Cyber Risk Is Business Risk on the gap between compliance and security, and this is what that gap looks like in practice: a signed agreement in a file cabinet, and a stranger inside the AWS environment for sixteen days. The agreement told you who would be responsible after the fact. It told you nothing about whether the vendor's cloud configuration could be walked through by someone with a stolen credential and a free afternoon.
Aesto has not said how the attacker got in. No group has claimed it. So I am not going to speculate about the mechanism. What I will say is that "we had a BAA" is going to be the first sentence in thirty different incident summaries, and the second sentence is going to be "and 9.5 million records left anyway."
Three Questions, Pointed at the Storage Unit
The framework I ask boards to use is three questions. Here is how they land on this incident.
What are we protecting? Not "patient data" in the abstract. The specific question is: what data have we handed to a third party that we are no longer touching day to day? Retired systems, acquired practices, wound-down service lines, old billing platforms. If your CISO cannot produce that list in a week, the list does not exist.
What happens if we lose it? For a covered entity, the answer is not "the vendor handles it." The answer is: our name, our patients, our regulator, our plaintiffs' bar. Aesto's clients are learning what it costs to be responsible for a breach they did not have, at a company they may not have thought about since the contract was signed.
Who decides? When the vendor calls on a Friday to say your archived records were in the affected environment, someone in your organization has to decide whether to let the vendor send the letters or send them yourself, what to tell the state attorney general, and what to tell the board. Several Aesto clients chose to notify on their own. That is a judgment call about control and reputation, and it should be made before the phone rings, not after.
What to Ask Your CISO This Week
Ask for the inventory of data held by third parties where the underlying business relationship is dormant — archived, migrated, acquired, retired. Not the active vendor list. The other one.
Ask whether any of those vendors have been security-reviewed in the past two years, and whether the review looked at their cloud environment or just at their SOC 2 cover letter.
Ask what the data retention requirement actually is for each archive. A surprising amount of legacy health data is held past any legal obligation because deleting it was nobody's project. Data you no longer hold cannot be stolen from a vendor you no longer pay.
Ask who signs the patient letter if one of those vendors is breached, and whether that person knows it.
Aesto Health will absorb its share of the damage. The thirty hospitals will absorb theirs, and most of them have less to absorb it with. The difference between the two groups is that Aesto knew it was holding 9.5 million records. Some of its clients are probably only now finding out how many of their own patients were in the box.