Were you recently affected by a data breach?

Ellenville Regional Hospital Data Breach

Ellenville Regional Hospital notified patients that a vendor’s data security incident may have exposed their protected health information. Learn what happened and what you can do.

Ellenville Regional Hospital
Date of Breach: December 2, 2025 to December 18, 2025 (at vendor Aesto, LLC); notification mailed September 16, 2026
CAU logo

Who was affected:

Clients of Ellenville Regional Hospital

Impacted Data:

Name, Social Security number, date of birth, medical record number, hospital unit and physician name (varied by individual)

Westchester Ellenville Hospital, doing business as Ellenville Regional Hospital (ERH), located in Ellenville, New York, notified affected patients of a data security incident that occurred at a third-party vendor, Aesto, LLC, which provides healthcare data migration and archiving services to the hospital. Healthcare providers that rely on outside vendors to manage patient records carry a continuing responsibility to ensure that vendor is protecting that information, and when an incident like this occurs, patients deserve a clear explanation of what happened and what they can do next.

Ellenville Regional Hospital’s Data Breach Investigation

ERH was notified on or around June 26, 2026 by Aesto that a network security incident occurred within Aesto’s Amazon Web Services infrastructure between approximately December 2 and December 18, 2025, in which an unauthorized actor may have accessed and/or acquired a limited amount of protected health information stored on Aesto’s network. Aesto engaged outside cybersecurity professionals to investigate and confirmed the scope of the incident through an extensive forensic investigation and manual document review completed on May 26, 2026.

Vendors that provide data migration, archiving, and similar back-office services to hospitals and other healthcare providers are attractive targets for cybercriminals because a single compromise can expose records belonging to patients of many different healthcare organizations that all rely on the same vendor. This kind of third-party vendor incident has become increasingly common in healthcare, since providers frequently outsource records management and other administrative functions to specialized vendors rather than handling every function in-house.

Aesto has stated it has no evidence that any of the affected information has been misused since the incident occurred, and reported closing the security gaps that allowed the unauthorized access, deleting the impacted cloud functions the intruder had modified, rotating affected credentials, and removing any unauthorized files the intruder had uploaded. ERH, for its part, engaged legal counsel to help assess the situation, request additional information from Aesto, and take steps to protect its patients following notification.

Notification letters to affected individuals were mailed by U.S. mail beginning September 16, 2026. ERH is offering affected patients complimentary credit monitoring and identity theft protection services through IDX for 24 months as a precaution, even though there is no confirmed evidence that any information has been misused to date.

Patients who receive a notification letter from ERH are encouraged to enroll in the offered monitoring services promptly and to remain alert to phishing attempts referencing this breach, since scammers frequently use news of a data breach to make follow-up scams appear more credible. Regularly reviewing account and insurance statements for unfamiliar activity is a reasonable precaution even where the exact scope of the exposed data for a given individual has not been detailed in the notification letter.

When Did This Breach Occur?

The underlying security incident at Aesto occurred between approximately December 2, 2025 and December 18, 2025. Aesto notified ERH of the incident on or around June 26, 2026, and confirmed the results of its forensic investigation on May 26, 2026. ERH’s notification letters to the Massachusetts Attorney General and to affected patients are dated September 16, 2026.

What Information Was Breached?

The information potentially impacted varied by individual, but may have included a patient’s full name, Social Security number, date of birth, medical record number, and treating hospital unit or physician name.

What You Can Do

ERH, through Aesto, is offering affected individuals a complimentary membership in single-bureau credit monitoring and identity theft protection services through IDX. Consider taking the following steps:

  • Enroll in the complimentary credit monitoring services offered in your notification letter before the enrollment deadline.
  • Regularly review your financial account statements and credit reports for unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus.
  • Be cautious of unsolicited calls, texts, or emails referencing this breach, which may be phishing attempts.

File a Data Breach Lawsuit Against Ellenville Regional Hospital

If you received a notification letter from Ellenville Regional Hospital or believe your information may have been involved in this event, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Unauthorized access: on or around September 17, 2026 (claimed by ransomware group Akira)
Date of Breach: Unauthorized access: December 2025 - April 16, 2026 (vendor: Sefas Innovation, Inc.)
Date of Breach: Not disclosed; publicly reported via dark web leak site posting in September 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.