Patients of more than two dozen U.S. healthcare providers may be covered by proposed class actions alleging Aesto Health, a Birmingham, Alabama medical records archiving vendor, failed to protect patient data exposed in a December 2025 breach of its cloud systems. No class has been certified and there is nothing to file yet.
This article describes class action complaints. The statements below are unproven allegations. Aesto, LLC and the healthcare providers named alongside it have not been found liable, there is no certified class, and nothing to claim at this time. This page is informational and is not legal advice.
Free settlement alerts
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Aesto works behind the scenes for doctors’ offices, clinics and hospitals, moving and archiving records from old computer systems. Patients usually have no direct relationship with it. If a provider you saw was an Aesto client and your records sat in the files that were accessed, your notice may come from Aesto, from the provider, or from both.
Possibly. Aesto’s own list of affected providers has grown with each update, and state filings and several complaints name organizations that were not on it, including Everside Health, VillageMD, Tapestry 360 Health, Murfreesboro Medical Clinic and Grant County Public Hospital District #2. The notification letter is the most reliable sign your records were involved.
The sample letter filed in South Carolina offers 12 months of Privacy Solutions ID through Epiq at no cost, with enrollment instructions in the letter itself. Enrolling does not affect whether you could take part in any future class settlement. Keep the letter either way, because a settlement claim form may ask for an identifier printed on it.
Different patients and law firms filed their own complaints, and several also sued the specific provider whose patients they are. Because every case names Aesto and was filed in the same Birmingham court, they are good candidates to be combined into one case with interim lead counsel. OpenClassActions.com could not confirm whether a consolidation order has been entered as of September 28, 2026.
Several complaints say yes. They point to a 2022 incident in which, they allege, an intruder had access to Aesto systems from late December 2021 until March 8, 2022 and copied files that included radiology reports, and which was reported to federal regulators as affecting about 17,400 patients. The plaintiffs use that history to argue the December 2025 breach was foreseeable. Aesto has not been found liable for either incident.