Westchester Ellenville Hospital, doing business as Ellenville Regional Hospital (ERH), located in Ellenville, New York, notified affected patients of a data security incident that occurred at a third-party vendor, Aesto, LLC, which provides healthcare data migration and archiving services to the hospital. Healthcare providers that rely on outside vendors to manage patient records carry a continuing responsibility to ensure that vendor is protecting that information, and when an incident like this occurs, patients deserve a clear explanation of what happened and what they can do next.
Ellenville Regional Hospital’s Data Breach Investigation
ERH was notified on or around June 26, 2026 by Aesto that a network security incident occurred within Aesto’s Amazon Web Services infrastructure between approximately December 2 and December 18, 2025, in which an unauthorized actor may have accessed and/or acquired a limited amount of protected health information stored on Aesto’s network. Aesto engaged outside cybersecurity professionals to investigate and confirmed the scope of the incident through an extensive forensic investigation and manual document review completed on May 26, 2026.
Vendors that provide data migration, archiving, and similar back-office services to hospitals and other healthcare providers are attractive targets for cybercriminals because a single compromise can expose records belonging to patients of many different healthcare organizations that all rely on the same vendor. This kind of third-party vendor incident has become increasingly common in healthcare, since providers frequently outsource records management and other administrative functions to specialized vendors rather than handling every function in-house.
Aesto has stated it has no evidence that any of the affected information has been misused since the incident occurred, and reported closing the security gaps that allowed the unauthorized access, deleting the impacted cloud functions the intruder had modified, rotating affected credentials, and removing any unauthorized files the intruder had uploaded. ERH, for its part, engaged legal counsel to help assess the situation, request additional information from Aesto, and take steps to protect its patients following notification.
Notification letters to affected individuals were mailed by U.S. mail beginning September 16, 2026. ERH is offering affected patients complimentary credit monitoring and identity theft protection services through IDX for 24 months as a precaution, even though there is no confirmed evidence that any information has been misused to date.
Patients who receive a notification letter from ERH are encouraged to enroll in the offered monitoring services promptly and to remain alert to phishing attempts referencing this breach, since scammers frequently use news of a data breach to make follow-up scams appear more credible. Regularly reviewing account and insurance statements for unfamiliar activity is a reasonable precaution even where the exact scope of the exposed data for a given individual has not been detailed in the notification letter.
When Did This Breach Occur?
The underlying security incident at Aesto occurred between approximately December 2, 2025 and December 18, 2025. Aesto notified ERH of the incident on or around June 26, 2026, and confirmed the results of its forensic investigation on May 26, 2026. ERH’s notification letters to the Massachusetts Attorney General and to affected patients are dated September 16, 2026.
What Information Was Breached?
The information potentially impacted varied by individual, but may have included a patient’s full name, Social Security number, date of birth, medical record number, and treating hospital unit or physician name.
What You Can Do
ERH, through Aesto, is offering affected individuals a complimentary membership in single-bureau credit monitoring and identity theft protection services through IDX. Consider taking the following steps:
- Enroll in the complimentary credit monitoring services offered in your notification letter before the enrollment deadline.
- Regularly review your financial account statements and credit reports for unfamiliar activity.
- Consider placing a fraud alert or credit freeze with the three major credit bureaus.
- Be cautious of unsolicited calls, texts, or emails referencing this breach, which may be phishing attempts.
File a Data Breach Lawsuit Against Ellenville Regional Hospital
If you received a notification letter from Ellenville Regional Hospital or believe your information may have been involved in this event, you may have legal options available to you.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.