Data Breach · Lawsuit Filed

Aesto Health Data Breach Lawsuits — At Least 11 Class Actions Over a Vendor Hack Affecting 9.5M People

Published September 28, 2026

Patients of more than two dozen U.S. healthcare providers may be covered by proposed class actions alleging Aesto Health, a Birmingham, Alabama medical records archiving vendor, failed to protect patient data exposed in a December 2025 breach of its cloud systems. No class has been certified and there is nothing to file yet.

Hospital corridor, illustrating the Aesto Health data breach lawsuits
▼ Allegations Only · No Settlement Yet

This article describes class action complaints. The statements below are unproven allegations. Aesto, LLC and the healthcare providers named alongside it have not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.

What Is This About?

Aesto, LLC, which does business as Aesto Health, is a Birmingham, Alabama company that moves and archives patient records for hospitals, clinics and physician practices when they change computer systems. It says an unauthorized actor got into part of its Amazon Web Services environment between about December 2 and December 18, 2025, and that files holding protected health information for patients of its provider clients may have been viewed or taken.

Aesto told federal health regulators that more than 9.5 million people were affected, according to one of the complaints. Between July 23 and September 14, 2026, patients filed at least 11 proposed class actions in the U.S. District Court for the Northern District of Alabama, which covers Birmingham. Every case names Aesto, and six of them also name the specific provider whose patients brought the suit. The cases are at the complaint stage. There is no settlement and nothing to claim.

Status Complaints Filed · No Settlement At least 11 proposed class actions in the Northern District of Alabama, filed July 23 – September 14, 2026
People Affected More than 9.5 million Figure Aesto reported to the HHS Office for Civil Rights, as cited in one complaint
Data Involved Names, dates of birth, medical and health insurance information, Social Security numbers Also driver’s license, taxpayer ID and financial account numbers for some people · varies by person
Can I Claim? No — nothing to claim yet

What Aesto Has Disclosed

Aesto’s public notice, dated June 24, 2026, lays out the timeline. It detected unauthorized activity on or about December 18, 2025, contained it, and brought in outside cybersecurity firms. After a forensic investigation and a manual review of the documents involved, it confirmed on May 26, 2026 that the intruder had access from about December 2 through December 18, 2025. It began notifying its provider clients on June 26, 2026, and says it has no evidence that anyone’s information has been used for identity theft or fraud.

The notice lists the kinds of data in the affected files: full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government ID numbers and Social Security numbers. Aesto says the mix differs from person to person. A sample letter to Everside Health patients, filed with South Carolina’s Department of Consumer Affairs and dated July 31, 2026, lists name, contact information, date of birth, Social Security number and, for some people, medical record number. That letter offers 12 months of Privacy Solutions ID identity monitoring through Epiq at no cost.

State filings show how far the breach reached. The complaints cite Aesto reports to state attorneys general covering 37,253 people in Washington, 730 in Oregon and 91 in Vermont. One complaint says VillageMD told New Hampshire’s attorney general that names and Social Security numbers of 107,349 of its patients were involved, and the Everside Health sample letter says about 119 Rhode Island residents were being notified.

Which Healthcare Providers Were Affected?

Aesto posts a list of affected clients, and it has grown over time. As of its September 8, 2026 update, the list named these 28 organizations:

• G.I. Medicine Associates, P.C.
• Catalyst Physician Group
• Mountrail County Medical Center
• Ninilchik Traditional Council Community Clinics
• My Doctor, LLC
• Sterling Health Solutions
• Henry County Hospital
• Midtown Community Health Center
• Little River Memorial Hospital
• Graham County Hospital
• Missoula Community Health Services Inc. (Mineral Community Hospital)
• Monroe Health Center
• Mid-South OB-GYN, PLLC
• Women’s Health Associates, Inc.
• Together Women’s Health Medical Group of Alabama, PC
• Together Women’s Health Medical Group, PC
• Effingham Obstetrics & Gynecology Associates, PLLC
• Main Street Medical Services, PLLC
• Rural Health Resources of Jackson County Inc. (Holton Community Hospital)
• Park West Health Systems, Inc.
• Marana Health
• Greenwood County Hospital
• Gila Health Resources, LLC
• Edwards County Medical Center
• Ellenville Regional Hospital
• Shenandoah Valley Medical System Inc.
• Texas Spine Consultants, LLP
• Nebraska Orthopedic Center, P.C.

The list is not the whole picture. State breach filings and the complaints name other organizations whose patients were notified, including Everside Health, Village Practice Management Company (VillageMD), Tapestry 360 Health, Murfreesboro Medical Clinic, Genesis OB/GYN and Grant County Public Hospital District #2. Several complaints allege that Aesto’s website left some of those names off its list. Anyone who gets a letter should go by the letter, not by whether a provider appears here.

The Lawsuits

These cases against Aesto are on the Northern District of Alabama docket. Where a complaint also sues a healthcare provider, the co-defendant is noted:

• No. 2:26-cv-01303, filed July 23, 2026 (the first-filed case)
• No. 2:26-cv-01547, filed August 31, 2026 · also names Genesis OB/GYN, PLLC
• No. 2:26-cv-01556, filed August 31, 2026 · also names Gila Health Resources
• No. 2:26-cv-01557, filed August 31, 2026 · also names Shenandoah Valley Medical System, Inc.
• No. 2:26-cv-01549, filed September 1, 2026 · also names Everside Health, LLC
• No. 2:26-cv-01558, filed September 1, 2026 · also names Village Practice Management Company, LLC (VillageMD)
• No. 2:26-cv-01576, filed September 2, 2026
• No. 2:26-cv-01583, filed September 2, 2026
• No. 2:26-cv-01584, filed September 3, 2026 · also names Murfreesboro Medical Clinic, P.A.
• No. 2:26-cv-01650, filed September 11, 2026
• No. 2:26-cv-01659, filed September 14, 2026

OpenClassActions.com read seven of the complaints in full. Two of them propose a single nationwide class of everyone whose information was compromised. The five that also sue a provider are nearly identical to one another and propose two groups: an Aesto class of people living anywhere in the U.S. except Alabama, and a separate class of that provider’s own patients. This list covers the dockets OpenClassActions.com has confirmed, and more related suits may have been filed. The case captions and docket links are listed under Sources below.

What the Complaints Allege

The plaintiffs claim Aesto did not use reasonable safeguards for the records it held, pointing to its public statements about HITRUST certification and SOC 2 audits and arguing that the intrusion itself shows those protections fell short. They allege Aesto failed to train staff, failed to catch the intruder for about 16 days, and waited roughly six months after the attack began before notifying anyone. The suits that also name a provider make the same claims against that provider.

Several complaints also point to a 2022 incident they say Aesto reported to federal regulators as affecting about 17,400 patients, and argue that history made another breach foreseeable. The legal claims include negligence, negligence per se under the FTC Act and HIPAA, breach of implied contract and unjust enrichment, and the provider suits add invasion of privacy and breach of fiduciary duty. The plaintiffs seek damages, restitution, stronger security measures, longer-term credit monitoring and attorneys’ fees.

All of these are allegations. None of them has been proven, and OpenClassActions.com found no ruling on whether any claim can go forward.

What Happens Next

With this many suits over one incident in one courthouse, the usual next step is a motion to consolidate them and appoint interim lead counsel, followed by a single amended complaint and then a motion to dismiss. Most of the complaints OpenClassActions.com reviewed are assigned to the same district judge. Some breach cases settle within a year or two, some are dismissed, and some take longer; there is no way to say which path this one will take. If a settlement is reached, class members would receive notice and a claim process would open, and this page will be updated.

In the meantime, the data breach notice guide covers what to do after Social Security numbers and medical information are exposed, and the data breach settlement tracker lists healthcare breach settlements that are open for claims now. The Perry Johnson & Associates lawsuit is a similar case in which a records vendor, not the providers themselves, was breached.

Questions

I never used Aesto Health. Why did I get a letter about it?

Aesto works behind the scenes for doctors’ offices, clinics and hospitals, moving and archiving records from old computer systems. Patients usually have no direct relationship with it. If a provider you saw was an Aesto client and your records sat in the files that were accessed, your notice may come from Aesto, from the provider, or from both.

My provider is not on Aesto’s list. Could I still be affected?

Possibly. Aesto’s own list of affected providers has grown with each update, and state filings and several complaints name organizations that were not on it, including Everside Health, VillageMD, Tapestry 360 Health, Murfreesboro Medical Clinic and Grant County Public Hospital District #2. The notification letter is the most reliable sign your records were involved.

Should I sign up for the free identity monitoring in the letter?

The sample letter filed in South Carolina offers 12 months of Privacy Solutions ID through Epiq at no cost, with enrollment instructions in the letter itself. Enrolling does not affect whether you could take part in any future class settlement. Keep the letter either way, because a settlement claim form may ask for an identifier printed on it.

Why are so many separate lawsuits being filed?

Different patients and law firms filed their own complaints, and several also sued the specific provider whose patients they are. Because every case names Aesto and was filed in the same Birmingham court, they are good candidates to be combined into one case with interim lead counsel. OpenClassActions.com could not confirm whether a consolidation order has been entered as of September 28, 2026.

Has Aesto been hit by a data breach before?

Several complaints say yes. They point to a 2022 incident in which, they allege, an intruder had access to Aesto systems from late December 2021 until March 8, 2022 and copied files that included radiology reports, and which was reported to federal regulators as affecting about 17,400 patients. The plaintiffs use that history to argue the December 2025 breach was foreseeable. Aesto has not been found liable for either incident.

Sources

• Aesto Health, Notice of Data Security Incident (June 24, 2026) — timeline, data types and notification dates.
• Aesto Health, Covered Entities Identified (updated September 8, 2026) — list of affected provider clients.
• Sample consumer notification letter for Everside Health patients, filed with the South Carolina Department of Consumer Affairs — data elements and identity monitoring offer.
• U.S. Department of Health and Human Services, Office for Civil Rights breach portal — federal breach report listing.
• Koester v. Aesto LLC, No. 2:26-cv-01303 (N.D. Ala. filed July 23, 2026) — CourtListener docket.
• McDaniel v. Aesto LLC, No. 2:26-cv-01547 (N.D. Ala. filed Aug. 31, 2026) — CourtListener docket.
• Herrera v. Aesto LLC, No. 2:26-cv-01556 (N.D. Ala. filed Aug. 31, 2026) — CourtListener docket.
• Pollard v. Aesto LLC, No. 2:26-cv-01557 (N.D. Ala. filed Aug. 31, 2026) — CourtListener docket.
• Doe v. Aesto LLC, No. 2:26-cv-01549 (N.D. Ala. filed Sept. 1, 2026) — CourtListener docket.
• Reyes v. Aesto LLC, No. 2:26-cv-01558 (N.D. Ala. filed Sept. 1, 2026) — CourtListener docket.
• Lott v. Aesto LLC, No. 2:26-cv-01576 (N.D. Ala. filed Sept. 2, 2026) — CourtListener docket; source of the HHS figure.
• Wilson v. Aesto LLC, No. 2:26-cv-01583 (N.D. Ala. filed Sept. 2, 2026) — CourtListener docket.
• Class Action Complaint, Simpson v. Aesto LLC, No. 2:26-cv-01584 (N.D. Ala. filed Sept. 3, 2026) — complaint PDF via CourtListener RECAP.
• Meadows v. Aesto LLC, No. 2:26-cv-01650 (N.D. Ala. filed Sept. 11, 2026) — CourtListener docket.
• Whitfield v. Aesto LLC, No. 2:26-cv-01659 (N.D. Ala. filed Sept. 14, 2026) — CourtListener docket.

For more class actions keep scrolling below.
Status Complaints filed · no settlement
Case Title Koester v. Aesto LLC (first-filed of at least 11)
Case Number 2:26-cv-01303
Court U.S. District Court, Northern District of Alabama
Date Filed July 23, 2026
Official Notice Aesto Health breach notice

More Healthcare Data Breach Lawsuits