Ocracoke Health Center recently notified patients that Aesto, LLC d/b/a Aesto Health, a company that provides healthcare data migration and archiving services on behalf of Ocracoke Health Center and other healthcare providers, experienced a network security incident that may have exposed patients’ personal and protected health information.
Healthcare providers that rely on outside vendors to migrate, store, or archive patient records take on a responsibility to ensure those vendors safeguard that information, and when an incident like this occurs, affected patients deserve clear answers about what happened and what steps they can take next.
Ocracoke Health Center’s Data Breach Investigation
According to Aesto Health’s public notice, the company discovered a network security incident affecting a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Aesto immediately contained the incident and engaged outside cybersecurity experts to determine what personal information, if any, was involved.
After an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026, that between approximately December 2, 2025, and December 18, 2025, protected health information belonging to patients of various healthcare provider clients, including Ocracoke Health Center, stored within Aesto’s network may have been accessed or acquired by an unauthorized party. Aesto began notifying its affected healthcare provider clients on June 26, 2026, so that each provider could in turn notify their own affected patients.
Aesto’s notice states that the information involved varied by individual and could include full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and, for a limited number of individuals, Social Security numbers. The company says it has no evidence of any identity theft or financial fraud related to this incident, though it is notifying affected individuals out of an abundance of caution.
State regulatory filings related to this incident report that approximately 29 Vermont residents were among those affected, a figure that reflects only the state-specific count of residents notified through that state’s own regulatory process. Because Aesto’s breach affected patients across numerous healthcare provider clients nationwide, the total number of individuals affected across all states is likely substantially larger than any single state’s reported figure.
Data breaches involving third-party healthcare data vendors have become an increasingly common and serious concern in recent years, since a single vendor’s systems can hold sensitive records belonging to patients of many separate healthcare providers at once. When a vendor like Aesto experiences an intrusion, the resulting notifications can ripple out to patients of dozens of unrelated clinics, hospitals, and health centers that had no direct role in the vendor’s own security practices, yet whose patients’ data was nonetheless exposed as a result.
The combination of medical information, government identification numbers, and financial account details reported in this incident is particularly sensitive, since this type of data can enable both traditional identity theft and medical identity theft, in which a bad actor uses a victim’s identifying information to fraudulently obtain healthcare services or submit fraudulent insurance claims in the victim’s name.
When Did This Breach Occur?
Aesto Health states that unauthorized access to its network occurred between approximately December 2, 2025, and December 18, 2025, and that it discovered the incident on December 18, 2025. The company confirmed that patient information was involved on May 26, 2026, and began notifying its affected healthcare provider clients, including Ocracoke Health Center, on June 26, 2026.
What Information Was Breached?
Aesto’s notice identifies the following categories of information as potentially involved, noting that the specific elements varied by individual: full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and, for a limited number of individuals, Social Security numbers.
What You Can Do
If you received a letter from Ocracoke Health Center about this breach, consider taking the following steps:
- Review your explanation of benefits statements for services you do not recognize and follow up with your insurance company or provider about any discrepancies.
- Monitor your email, phone, and mail for suspicious contact attempts referencing your personal or medical details.
- Be cautious of unsolicited messages asking you to click a link, download an attachment, or provide additional personal information.
- Review your financial accounts and credit reports for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus if you are concerned about identity theft.
- Keep a copy of your notification letter and any related correspondence in case you need it later.
File a Data Breach Lawsuit Against Ocracoke Health Center
If you received a data breach notification letter from Ocracoke Health Center, or if you believe your personal information was exposed as a result of the Aesto Health incident, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.