Mineral Community Hospital, operated by Missoula Community Health Services, Inc. in Montana, has notified patients that their personal information may have been exposed in connection with a data security incident at Aesto, LLC, a vendor that provides healthcare data migration and archiving services. Hospitals and the outside vendors they rely on both carry a responsibility to keep patients’ personal information secure, whether that information sits on the hospital’s own systems or with a third party handling matters on the hospital’s behalf.
Mineral Community Hospital’s Data Breach Investigation
According to the notification letter sent to affected individuals, Aesto experienced a network security incident on or about December 18, 2025 that impacted a limited portion of its Amazon Web Services infrastructure. Aesto says it commenced a prompt and thorough investigation, working closely with external cybersecurity professionals experienced in handling incidents of this kind. After an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026 that between on or about December 2, 2025 and December 18, 2025, a limited amount of protected health information belonging to Mineral Community Hospital patients, which was stored on Aesto’s network, may have been accessed and/or acquired by an unauthorized actor. Aesto has stated it has no evidence that any of the information has been misused.
Public reporting indicates the Aesto data security incident was significantly larger in scope than a single hospital, reportedly affecting more than 9.5 million patient records across dozens of healthcare provider clients nationwide, including Graham County Hospital, Henry County Hospital, and Little River Memorial Hospital, among many others. Aesto provides data migration and archiving services that allow hospitals and clinics to digitize and store patient records, meaning a single vendor-side security failure can expose sensitive information belonging to patients of many unrelated healthcare providers at once.
Data security incidents involving third-party healthcare vendors are a growing concern because hospitals and clinics increasingly rely on outside companies to manage, migrate, and archive electronic patient records. When a vendor like Aesto experiences a breach, the patients affected often have no direct relationship with the vendor itself and may not even be aware such a company held their information until they receive a notification letter months after the underlying incident occurred. That gap between when an incident happens and when patients are actually informed can leave affected individuals unaware that their Social Security number or health information may be at risk during the exact window when it would be most useful for them to monitor their accounts and credit files closely.
Because protected health information cannot simply be cancelled and reissued the way a stolen credit card number can, exposure of this kind of data can create a long-lasting risk of identity theft, medical identity fraud, and targeted phishing attempts that reference a patient’s actual medical history to appear more credible. To help protect affected individuals, Mineral Community Hospital is offering a complimentary single-bureau credit monitoring and identity theft protection membership. Patients who received a notification letter are encouraged to enroll in these services before the enrollment deadline stated in their letter, and to remain vigilant for signs their information has been misused even after the incident has faded from the news.
Multi-provider vendor breaches like this one also illustrate a broader pattern in healthcare data security: even a hospital or clinic with strong internal safeguards can still see its patients’ information exposed if a vendor it relies on for a back-office function, such as records migration or archiving, suffers its own security failure. Patients generally have no way to know which vendors a healthcare provider uses behind the scenes, which makes it especially important for affected individuals to take the protective steps outlined below rather than assume a breach notice from an unfamiliar company name is not worth acting on.
When Did This Breach Occur?
Aesto detected the network security incident on or about December 18, 2025, and determined it involved unauthorized access to data between approximately December 2, 2025 and December 18, 2025. Aesto’s forensic investigation concluded on May 26, 2026, at which point it confirmed that protected health information belonging to Mineral Community Hospital patients was affected. Notification letters to affected individuals were filed with the Massachusetts Attorney General in September 2026.
What Information Was Breached?
The information potentially impacted includes each affected patient’s full name, along with other protected health information. Aesto has stated it has no evidence that any of the information has been misused for identity theft or financial fraud as a direct result of this incident.
What You Can Do
If you received a notification letter regarding the Mineral Community Hospital/Aesto data breach, consider taking the following steps:
- Enroll in the complimentary credit monitoring and identity theft protection services offered in your notification letter before the stated deadline.
- Place a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion.
- Request and review a free copy of your credit report at annualcreditreport.com.
- Monitor your financial and medical accounts closely for any unauthorized activity.
- Report any suspected identity theft to your state Attorney General and the Federal Trade Commission.
File a Data Breach Lawsuit Against Mineral Community Hospital
If you received a data breach notification letter connected to Mineral Community Hospital or Aesto, you may be entitled to compensation. Companies and vendors that collect and store sensitive medical and financial information have a responsibility to keep it secure, and when that trust is broken, affected individuals deserve answers and accountability.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.