Lone Star Community Health Data Breach: 250,130 Patients — Is There a Lawsuit? (August 2026)
A vendor's cloud breach exposed a quarter-million Texas patients' Social Security numbers, medical and insurance data. Class-action firms are investigating. No settlement exists yet — this tracker follows the case.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened
Lone Star Community Health Center — a Conroe, Texas community health provider — reported to the Texas Attorney General on August 14, 2026 that 250,130 Texas residents connected to the center had personal and protected health information exposed. The breach happened at a vendor: Aesto Health experienced a network security incident in its Amazon Web Services infrastructure around December 18, 2025; forensics determined an unauthorized actor may have accessed and acquired data between December 2 and December 18, 2025. Aesto confirmed the scope on May 26, 2026 and told affected healthcare clients — including Lone Star — on June 26, 2026; patient letters followed by U.S. mail. Exposed categories: names, Social Security numbers, dates of birth, driver's license/government ID numbers, financial account numbers, medical information and health insurance information.
Case Details
As of August 17, 2026, no class action is confirmed filed. Edelson Lechtzin LLP announced an investigation on August 16, 2026 and is collecting affected patients. Vendor-caused healthcare breaches of this size (250K+) are a classic class-action profile — with both the health center and the vendor (Aesto Health) as potential defendants. This page tracks the docket from the first complaint on.
Current Status — Verified August 17, 2026
Who Is Affected?
250,130 Texas residents per the AG filing — current and former patients of Lone Star Community Health Center whose data lived in Aesto Health's systems. The official signal is a notification letter from Lone Star or Aesto Health. If you or your family received care at the center, watch your mail and keep any letter — it's your proof of membership.
What Could This Pay? (Honest Answer)
Case Timeline
- 1
December 2–18, 2025: The intrusion at Aesto Health
An unauthorized actor may have accessed and acquired data in the vendor's AWS infrastructure across roughly two weeks.
- 2
December 18, 2025: Detection
Aesto Health identifies the incident and begins its forensic investigation.
- 3
May 26, 2026: Scope confirmed
Aesto confirms what data was involved — about five months after the intrusion.
- 4
June 26, 2026: Healthcare clients notified
Aesto informs affected covered-entity clients, including Lone Star Community Health Center; patient letters follow by U.S. mail.
- 5
August 14, 2026: Texas AG filing — 250,130 affected
The report to the Texas Attorney General puts a number on the breach: a quarter-million Texans.
- 6
August 16, 2026: Firms open investigations
Edelson Lechtzin LLP announces its investigation and begins signing up affected patients.
- 7
What's next
First complaints (health center and/or vendor as defendants), likely consolidation, then the standard breach-litigation path. We update this page at each milestone.
Lone Star Breach Scams
Patient-data breaches draw medical-themed scams — the exposed details make them convincing.
Fake 'settlement claim' sites
No claims portal exists. Any payout form today is a scam. A real claims process would appear in court filings — and on this page.
Fake clinic or insurance calls
Callers may quote real appointment or insurance details. The health center won't call to ask for your SSN or bank data. Verify only through the number on your official documents.
Medical-bill collection fraud
Surprise bills for care you never received are the signature of medical identity theft. Don't pay — demand written validation, check your EOB statements, and report it.
Lone Star Health Breach FAQs
Is there a Lone Star Community Health settlement?
No. As of August 17, 2026 there is no settlement, no administrator, no fund — and no confirmed filed complaint. Edelson Lechtzin is investigating. We update this page when anything changes.
I never heard of Aesto Health — why is my data there?
Aesto Health is a technology vendor the health center used. Healthcare providers routinely store patient data with such vendors — and under HIPAA, both can bear responsibility when vendor systems are breached. That dual-defendant angle often strengthens these cases.
What data was exposed?
Per the filings: names, Social Security numbers, dates of birth, driver's license/government ID numbers, financial account numbers, medical information and health insurance information. Your letter states which fields were in your record.
What should I do right now?
(1) Enroll in any free monitoring your letter offers; (2) credit freezes at all three bureaus; (3) review every insurance EOB for services you never received; (4) keep records of anything suspicious — documented losses pay best.
My children were patients. Are they affected?
Community health centers serve many families, and the filing counts individuals — minors included. Child identity theft goes unnoticed for years; if your family gets letters, consider checking whether your children have credit files they shouldn't have.
How much could a settlement pay?
Unknown — no case exists yet. Healthcare breaches with SSN + medical data are among the stronger-paying categories; class size (250K) will shape per-person math. Anyone quoting a number today is guessing.
Do I need to sign up with a firm now?
No — a future class settlement would cover you automatically. Individual advice matters only for serious, documented identity theft traceable to this breach.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.