Aesto Health Data Breach: 9,540,683 Patients Across 35+ Providers
Most people who received a letter about this had never heard of Aesto Health. It is a Birmingham, Alabama company that migrates and archives patient records for clinics and hospitals — which means a single break-in reached 9,540,683 people at once. The list of affected providers is below, and it has kept growing. There is no settlement and no claim form.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened at Aesto Health
Aesto Health handles healthcare data migration and archiving: when a practice retires an old records system, a vendor like Aesto keeps that history readable. That makes its systems a single place holding many different providers' full patient files. An unauthorised party was inside part of Aesto's Amazon Web Services infrastructure between December 2 and December 18, 2025 and may have copied data during that window. Aesto detected the intrusion on or around December 18, 2025, finished determining the scope on May 26, 2026, and told its healthcare-provider clients on June 26, 2026. Patient letters began going out around August 25, 2026. Reported to the HHS Office for Civil Rights, the incident covers 9,540,683 individuals.
Case Details
No complaint against Aesto Health over this incident was docketed at our last check (September 7, 2026). Several plaintiffs' firms have opened public investigations and are taking intake — among them Edelson Lechtzin, Markovits Stock & DeMarco, Pittman Dutton Hellums Bradley & Mann, and Levi & Korsinsky. Individual providers have made their own regulator filings: Lone Star Community Health Center reported 250,130 Texas residents to the Texas Attorney General on August 14, 2026, and SpineZone — now Livara Health Medical Group — filed with the California Attorney General on August 25, 2026.
Status: Letters Are Out, No Settlement Exists
Is Your Provider on the List?
These are the healthcare providers known to have been affected. The list has grown as more providers identified themselves, so absence from it is not proof you are unaffected — the letter is the reliable signal.
• Edwards County Medical Center
• Effingham Obstetrics & Gynecology Associates
• Ellenville Regional Hospital
• Everside Health (~22,000 in Washington)
• Gila Health Resources
• Graham County Hospital
• Greenwood County Hospital
• Henry County Hospital
• Little River Memorial Hospital
• Livara Health Medical Group (formerly SpineZone)
• Lone Star Community Health Center
• Main Street Medical Services
• Marana Health
• Mid-South OB-GYN
• Midtown Community Health Center
• Missoula Community Health Services, dba Mineral Community Hospital
• Monroe Health Center
• Murfreesboro Medical Clinic
• My Doctor, LLC
• Nebraska Orthopedic Center
• Northern Inyo Healthcare District (Northern Inyo Hospital)
• North Florida Women's Care
• Park West Health Systems
• Quincy Valley Medical Center
• Rural Health Resources of Jackson County (Holton Community Hospital)
• Shenandoah Valley Medical System
• Stanislaus County Health Services Agency
• Sterling Health Solutions
• Surgeons Choice Medical Center
• Texas Spine Consultants
• Together Women's Health Medical Group of Alabama
• Together Women's Health Medical Group
• Valley Perinatal Services (Advanced Women's Care)
• Village Practice Management (Village Medical, 25,000+ patients)
• Women's Health Associates
If you received a notice naming Aesto Health, keep the letter and the envelope. It states which data fields were in your own record, and it is your proof of membership if a class is ever certified.
What These Cases Tend to Pay
Aesto Health Breach Timeline
- 1
December 2–18, 2025 — The Intrusion Window
An unauthorised party is inside part of Aesto's Amazon Web Services environment and may copy data.
- 2
December 18, 2025 — Detected
Aesto identifies the security incident and opens a forensic investigation.
- 3
May 26, 2026 — Scope Determined
Aesto concludes which protected health information was affected. Five months have passed since detection; patients still know nothing.
- 4
June 26, 2026 — Provider Clients Told
Aesto notifies the clinics and hospitals whose data it held. Each of them then has to notify its own patients.
- 5
August 14–25, 2026 — Regulators and Patients
Lone Star Community Health Center reports 250,130 Texas residents to the Texas Attorney General on August 14. Patient letters go out from around August 25, the day SpineZone files with California.
- 6
September 2026 — 9.5 Million on the Federal Record
The breach report to the HHS Office for Civil Rights puts the total at 9,540,683 individuals across at least 35 provider clients. Firms are recruiting; no complaint is docketed yet.
Three Traps Around This Breach
A nine-figure patient count and a vendor name nobody recognises is ideal ground for imposters:
“Aesto settlement claim form” pages
There is no settlement and no administrator, so there is nothing to claim. A page collecting your Social Security number for an Aesto payout is harvesting data, not filing anything.
Callers who already know your clinic
The affected-provider list is public, so a caller naming your doctor's office proves nothing about who they are. No legitimate administrator or law firm phones to ask for your full Social Security number, or for a payment to release funds.
The monitoring code, resold
Enrolment in the offered monitoring is free and uses the activation code printed on your own letter. Anyone charging a fee to activate or expedite it is not connected to the notice.
Aesto Health Breach — Questions People Actually Ask
What is Aesto Health, and why does it have my records?
Aesto Health is a Birmingham, Alabama company that handles healthcare data migration and archiving. When a clinic or hospital retires an old records system, a vendor like Aesto keeps that history accessible. You never signed up with them — your provider did, which is why the name on the letter is unfamiliar.
Is there an Aesto Health settlement I can claim?
No. There is no settlement, no fund, no administrator and no deadline. Firms are investigating and taking intake, but no complaint was docketed at our last check. If that changes, a court-appointed administrator contacts class members directly — you do not have to find them.
How many people were affected?
9,540,683 individuals, per the breach report to the HHS Office for Civil Rights. At least 35 healthcare provider clients were affected, and that count has been revised upward as more providers identified themselves.
What information was taken?
Per the notices: full names, Social Security numbers, partial dates of birth, driver's licence and state ID numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims and billing information, and health insurance information. Your own letter states which of those were in your record.
I got an envelope marked “Return to Kroll” — is that this breach?
Not necessarily, and the two should not be assumed to be the same mailing. “Return to Kroll, P.O. Box 980108, West Sacramento” is the return address Kroll uses for breach notices it mails on behalf of many different companies. The identity protection Aesto is offering runs through Epiq, not Kroll. Read the letter itself: its first paragraph names the company whose data was involved.
My provider is not on the list. Am I safe?
Not proven either way. The published list covers providers known to have been affected and it has grown over time. The letter is the reliable signal — if one arrives naming Aesto Health, keep it.
What should I do right now?
Freeze your credit at all three bureaus; it is free and reversible. Enrol in the monitoring using the code on your letter. Read the explanation-of-benefits statements from your health insurer for care you never received — that is how medical identity theft shows up. Keep the letter and the envelope.
Does the eight-month delay actually matter?
It is the part the investigating firms are focused on. The intrusion ended December 18, 2025 and most patients learned of it in late August 2026. Whether that delay was reasonable is a question for a court; the practical effect is that nobody could act during the period when stolen records are most useful.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Lone Star Community Health (250,130)
The Texas provider hit through Aesto — state filing and next steps
Return to Kroll, P.O. Box 980108
How to tell a breach notice from a settlement check
Data Breach Payout Estimator
What a breach pays by data type, plus 30+ tracked cases
Quantum Health Breach (2026)
Another healthcare vendor breach — firms investigating