Were you recently affected by a data breach?

Shenandoah Valley Medical System Data Breach

Shenandoah Valley Medical System, Inc. has notified patients that their personal and health information was exposed in a security incident at Aesto Health, a healthcare data vendor, between December 2 and December 18, 2025.

Shenandoah Valley Medical System
Date of Breach: December 2, 2025 - December 18, 2025
CAU logo

Who was affected:

Clients of Shenandoah Valley Medical System

Impacted Data:

Names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, taxpayer identification numbers, government identification numbers, Social Security numbers

Shenandoah Valley Medical System, Inc., doing business as Shenandoah Community Health, has notified certain patients that their personal information was involved in a data security incident affecting Aesto, LLC (doing business as Aesto Health), a vendor that provides healthcare data migration and archiving services. Shenandoah Valley Medical System was one of numerous healthcare providers whose patient data was stored on Aesto’s network at the time of the incident.

Companies that store sensitive patient data, whether directly or through a third-party vendor, have a responsibility to safeguard it, and to notify affected individuals promptly when that trust is broken.

Shenandoah Valley Medical System’s Data Breach Investigation

According to a notice filed with the Vermont Attorney General’s Office, Aesto experienced a network security incident that impacted a limited portion of its Amazon Web Services infrastructure in December 2025. Aesto contained the incident upon discovery and engaged outside cybersecurity experts to investigate. After an extensive forensic review, Aesto confirmed on May 26, 2026, that certain protected health information belonging to patients of its various healthcare provider clients, including Shenandoah Valley Medical System, may have been accessed or acquired by an unauthorized party. Aesto began notifying its affected healthcare provider clients on June 26, 2026, and Shenandoah Valley Medical System has since reported the incident to state regulators, including Vermont, where 7 residents were identified as affected.

This incident illustrates a common pattern in healthcare data breaches: rather than a hospital or clinic’s own network being directly compromised, a third-party vendor that stores or processes patient records on the provider’s behalf is targeted instead. Because vendors like Aesto often serve dozens of healthcare organizations at once, a single vendor breach can expose patient data belonging to many separate providers and their patients across multiple states, which is why this notice was filed with Vermont’s Attorney General even though the underlying security incident occurred on Aesto’s own infrastructure rather than at a Vermont-based facility.

Breaches involving healthcare data vendors are particularly concerning because the exposed information often includes a combination of medical details and identity-verifying data, such as Social Security numbers and government-issued identification numbers, that together create a heightened risk of both medical identity theft and traditional financial fraud. The months-long gap between the incident’s occurrence in December 2025 and formal notification in mid-2026 also reflects the reality that forensic review and identifying every affected individual across a large vendor’s client base can take considerable time, even when a vendor moves promptly to contain unauthorized access.

When Did This Breach Occur?

The underlying security incident at Aesto occurred between approximately December 2, 2025, and December 18, 2025. Aesto detected unauthorized activity and confirmed on May 26, 2026, following forensic investigation, that patient data may have been accessed or acquired during that window. Aesto began notifying its affected Covered Entity clients, including Shenandoah Valley Medical System, on June 26, 2026, more than six months after the incident occurred.

What Information Was Breached?

According to Aesto’s notice, the information involved varied by individual but could include full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. Vermont’s Attorney General filing identified 7 Vermont residents connected to Shenandoah Valley Medical System as affected by this incident; the total number of individuals affected nationwide across all of Aesto’s covered healthcare provider clients has not been separately disclosed in this notice.

What You Can Do

If you are a patient of Shenandoah Valley Medical System / Shenandoah Community Health and are concerned about this incident, consider the following steps:

  • Review any notification letter you receive for the specific categories of your information that were involved
  • Place a fraud alert or security freeze with the three major credit bureaus (Equifax, Experian, TransUnion)
  • Request and review your free credit reports at annualcreditreport.com for unfamiliar activity
  • Review your health insurance explanation of benefits statements for services you do not recognize
  • Report any suspicious account activity to your local law enforcement agency and the FTC

File a Data Breach Lawsuit Against Shenandoah Valley Medical System

Attorneys are investigating whether a class action lawsuit can be filed on behalf of patients whose personal information was compromised in the Shenandoah Valley Medical System/Aesto Health data breach. If the breach is found to have resulted from inadequate data security practices, affected individuals may be entitled to compensation for their losses, including the time and expense associated with monitoring their accounts and guarding against identity theft.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 2026 (reported via dark web leak site claim; not confirmed by the company)
Date of Breach: Not publicly disclosed as of August 2026
Date of Breach: May 4, 2026 (date of discovery)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.