Stanislaus County Health Services Agency (SCHSA) has begun notifying patients that some of their protected health information may have been exposed as a result of a data security incident at a third-party vendor that stores and manages medical records on the agency’s behalf. Organizations entrusted with sensitive medical and personal data have a responsibility to protect it, and when that trust is broken, affected individuals deserve clear answers about what happened and what comes next.
Stanislaus County Health Services Agency’s Data Breach Investigation
According to a notification letter filed with the California Attorney General’s Office, the incident did not originate within SCHSA’s own systems. Instead, it occurred at Aesto, LLC, a company that provides healthcare data migration and archiving services to SCHSA and other healthcare providers. Aesto reported that on or about December 18, 2025, it experienced a network security incident affecting a limited portion of its Amazon Web Services infrastructure. Following an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026 that between on or about December 2 and December 18, 2025, an unauthorized actor may have accessed or acquired a limited amount of protected health information belonging to SCHSA patients that was stored on Aesto’s network. Aesto notified SCHSA of the incident on July 10, 2026, which in turn triggered notice to affected patients.
Third-party vendor breaches like this one are an increasingly common way for sensitive healthcare data to be exposed. Healthcare providers frequently rely on outside companies for data storage, migration, and archiving services, which means a security failure at a single vendor can ripple out to affect the patients of many different healthcare organizations that never directly handled the compromised systems themselves. This incident illustrates that risk: a single network intrusion at Aesto has reportedly required notifications to patients of multiple covered entities across different states, each filed separately with the relevant state regulator.
The gap between when unauthorized access allegedly occurred (December 2025) and when affected individuals were formally notified (mid-2026) is also common in incidents involving compromised health data. Thorough forensic review of large volumes of records to determine exactly whose information was involved, and what specific data elements were exposed, can take many months, particularly when a third-party vendor is coordinating that review across numerous client organizations at once. While SCHSA states it has no evidence that any of the potentially exposed information has been misused, the sensitivity of medical data means it can retain value to bad actors for identity theft, medical fraud, and phishing schemes well after a breach initially occurs, which is why prompt and informed action from affected patients matters even in the absence of confirmed misuse.
Government health agencies and their vendors are frequent targets for cybercriminals precisely because the records they manage are so information-rich. A single health services database can combine names, dates of birth, medical histories, and sometimes financial or insurance details in one place, making it a valuable target for actors seeking to commit medical identity theft, fraudulently obtain healthcare services, or file fraudulent insurance claims in a victim’s name. When a vendor like Aesto centralizes archived records for many different healthcare providers on shared infrastructure, a single successful intrusion can multiply the impact well beyond what any one provider’s own systems would expose on their own.
Patients who receive a breach notification letter are also frequently targeted afterward by follow-up phishing attempts, in which scammers impersonate the breached organization, a credit monitoring provider, or a law firm to try to extract additional personal information or payment. Recipients of a genuine SCHSA or Aesto notification letter should verify any follow-up communication independently, using contact information from the official letter itself or the agency’s own published channels, rather than clicking links or calling numbers provided in unsolicited follow-up messages. Regulatory notification timelines, like the one reflected in this filing with the California Attorney General, exist specifically so that affected individuals eventually receive a documented, verifiable account of the incident that can be checked against future communications claiming to be about the same breach.
When Did This Breach Occur?
Aesto has stated that the unauthorized access to its network occurred on or about December 2, 2025 through December 18, 2025. The company completed its forensic investigation and confirmed that patient data was involved on May 26, 2026, and notified SCHSA of the incident on July 10, 2026. SCHSA subsequently began mailing notification letters to affected patients and filed notice with the California Attorney General.
What Information Was Breached?
The notification letter confirms that each affected patient’s full name was involved. The letter references additional categories of personal or health information specific to each recipient, but the sample notice filed with the California Attorney General leaves the specific data elements as a fill-in-the-blank field rather than listing a single universal set that applied to every patient. Because Aesto provides data migration and archiving services, the type of information it stores can include protected health information such as medical record details in addition to basic identifying information. SCHSA and Aesto have not publicly disclosed a single, complete list of data types that applied to all affected individuals.
What You Can Do
If you received a notification letter from Stanislaus County Health Services Agency or Aesto, consider the following steps:
- Read the letter carefully to identify the specific data elements listed as compromised for you.
- Enroll in the complimentary credit monitoring and identity protection service referenced in your letter, if offered.
- Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
- Request a free copy of your credit report at annualcreditreport.com and review it for unfamiliar activity.
- Monitor your financial and medical statements closely for any signs of fraudulent use of your information.
- Report any suspected identity theft to the Federal Trade Commission at identitytheft.gov and to local law enforcement.
File a Data Breach Lawsuit Against Stanislaus County Health Services Agency
If your personal or medical information was compromised in this incident, you may have legal options available to you. Companies and agencies that collect and store sensitive data are expected to implement reasonable safeguards to protect it, and when a third-party vendor’s security failure exposes your information, you should not have to bear the resulting risk alone.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.