Four plaintiffs have filed three new proposed class action lawsuits against Aesto LLC, which does business as Aesto Health, and three healthcare organizations that used its data services. The lawsuits accuse the defendants of failing to protect patients’ personal and medical information and providing inadequate notice after learning that the information may have been compromised.
What happened
The three lawsuits were filed in the U.S. District Court for the Northern District of Alabama between August 31 and September 1, 2026, according to public court records.
John Doe filed the first lawsuit on behalf of his minor daughter against Aesto and Everside Health. Victoria Reyes and Angel Rodriguez filed the second case against Aesto and Village Practice Management Company, which does business as VillageMD. Fred Shatzoff filed the third lawsuit against Aesto and Allied Health MSO Holdco.
The complaints collectively allege negligence, negligence per se, breach of implied contract, invasion of privacy, unjust enrichment, and breach of fiduciary duty. Two also seek declaratory judgments, and all three demand jury trials.
Reyes and Rodriguez claim they experienced increased spam and scam emails, text messages, and phone calls after their information was exposed. They also allege that they spent time researching the incident, contacting Aesto’s response line, and taking steps to protect their accounts.
Doe and Shatzoff allege that their information has lost value and that they face an increased risk of identity theft and fraud. All four plaintiffs claim they will have to continue monitoring their financial and healthcare accounts.
Each complaint seeks to represent a nationwide class of affected individuals, excluding Alabama residents, and a separate class connected to the healthcare organization named in that lawsuit. These remain allegations, and the courts have not certified the proposed classes or determined that any defendant is liable.
The backstory
Aesto announced on June 24, 2026, that it had experienced a network security incident affecting part of its Amazon Web Services infrastructure. The company said it detected unauthorized activity on or about December 18, 2025, contained the incident, and engaged cybersecurity specialists.
Aesto determined on May 26, 2026, that an unauthorized actor may have accessed or acquired protected health information between December 2 and December 18, 2025. The information varied by person and could include names, dates of birth, medical and health insurance information, Social Security numbers, driver’s license numbers, financial account numbers, and government identification numbers.
Aesto said it found no evidence of identity theft or financial fraud connected to the incident and began notifying affected healthcare clients on June 26. The plaintiffs allege that the notification delay prevented patients from taking earlier steps to protect themselves.
The HHS Office for Civil Rights breach portal lists Aesto as a business associate and states that the hacking or IT incident affected 9,540,683 individuals. The listing identifies the incident as under investigation and does not represent a finding that Aesto violated HIPAA.
Becker’s Hospital Review described it as “one of the largest healthcare breaches disclosed in 2026.”
Why it matters
A Paubox report on Continuum Health Alliance provides a similar example of litigation involving vendor-managed patient information. Continuum agreed to a proposed settlement capped at $1.3 million after multiple lawsuits were consolidated over unauthorized access to a server containing data from several provider practices. The incident affected approximately 377,119 patients of Consensus Medical Group. The court had not granted final approval when Paubox reported the agreement.
A peer-reviewed Healthcare (Basel) study states, “The frequency of healthcare data breaches, magnitude of exposed records, and financial losses due to breached records are increasing rapidly.” The Aesto cases could test whether alleged increases in scam communications, time spent responding to the breach, emotional distress, and the risk of future identity theft constitute legally recognized injuries sufficient for the claims to proceed.
The filing of a complaint does not establish wrongdoing. Aesto and the healthcare defendants may dispute the allegations, argue that the plaintiffs have not demonstrated concrete harm, and oppose certification of the proposed classes. The courts have not yet decided those questions.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
Is a network security incident always a data breach?
No, it becomes a data breach only when an investigation determines that protected or personal information was accessed, acquired, or disclosed without authorization.
Can a vendor breach affect patients from several healthcare organizations?
Yes, one vendor may store or process information for numerous providers, allowing a single incident to affect patients across multiple organizations.
What if the exposed information belongs to a child?
A parent or guardian can request the child’s credit reports, consider placing credit freezes, and watch for unexpected medical or insurance activity.
