PRIVACY ALERT: AWKO Law LLP Investigating Aesto Health Data Breach Affecting Over 9.5 Million Patient Records
PRIVACY ALERT: AWKO Law LLP Investigating Aesto Health Data Breach Affecting Over 9.5 Million Patient Records
SAN FRANCISCO--(BUSINESS WIRE)--AWKO Law LLP is investigating a data breach that led to unauthorized access to the sensitive information of 9,540,683 patients of clients of Aesto, LLC d/b/a Aesto Health (“Aesto”), an Alabama-based healthcare technology company. Aesto offers secure data migration, electronic health record (EHR) exchanges, and legacy data archiving services to healthcare providers and medical practices.
Between December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various covered entity clients stored within Aesto’s network was accessed and/or acquired by an unauthorized actor.
The following healthcare providers and medical practices are confirmed to have been impacted:
- Edwards County Medical Center
- Effingham Obstetrics & Gynecology Associates, PLLC
- Ellenville Regional Hospital
- Everside Health
- Gila Health Resources, LLC
- Graham County Hospital
- Greenwood County Hospital
- Henry County Hospital
- Kaniksu Community Health
- Little River Memorial Hospital
- Livara Health Medical Group (formerly SpineZone)
- Lone Star Community Health Center
- Main Street Medical Services, PLLC
- Marana Health
- Mid-South OB-GYN, PLLC
- Midtown Community Health Center
- Missoula Community Health Services Inc., dba Mineral Community Hospital
- Monroe Health Center
- Murfreesboro Medical Clinic
- My Doctor, LLC
- Nebraska Orthopedic Center, PC
- Northern Inyo Healthcare District d/b/a Northern Inyo Hospital
- North Florida Women’s Care
- Park West Health Systems, Inc.
- Quincy Valley Medical Center
- Rural Health Resources of Jackson County Inc. d/b/a Holton Community Hospital
- Shenandoah Valley Medical System Inc.
- Stanislaus County Health Services Agency
- Sterling Health Solutions
- Surgeons Choice Medical Center
- Texas Spine Consultants, LLP
- Together Women’s Health Medical Group of Alabama, PC
- Together Women’s Health Medical Group, PC
- Valley Perinatal Services LLC (Advanced Women’s Care)
- Village Practice Management (VillageMD; Village Medical)
- Women’s Health Associates, Inc.
Although the breach occurred in December 2025, Aesto and its affiliated entities did not notify impacted individuals until on or around June 24, 2026, which may have violated state and federal laws. The following data may have been compromised in the breach: full names, Social Security numbers, partial dates of birth, driver’s license numbers, state identification numbers, financial account numbers, taxpayer identification numbers, health records, medical histories, claims/billing information, and health insurance information.
If your personal information was impacted by this incident, you may be at risk of identity theft and other serious violations of your privacy. As a result, you may be entitled to money damages and an injunction requiring changes to Aesto’s cybersecurity practices.
If you received notification of this data breach or are affiliated with Aesto or the entities listed above and wish to obtain additional information about your legal rights, please contact us today at (415) 251-6804 or sdixit@awkolawllp.com.
Contacts
Sonum Dixit
AWKO Law LLP
sdixit@awkolawllp.com
Tel: 415-251-6804