Rural Health Resources of Jackson County, Inc., doing business as Holton Community Hospital, has notified patients that their personal and health information may have been exposed as part of a large data security incident at Aesto Health, a third-party vendor the hospital relies on for secure data migration and archiving services.
Healthcare providers that entrust patient records to outside vendors still bear responsibility for making sure that information is kept secure, and patients affected by this incident deserve a clear explanation of what happened and what options are available to them.
Holton Community Hospital’s Data Breach Investigation
Holton Community Hospital, operated by Rural Health Resources of Jackson County, Inc., is a
rural hospital serving Jackson County, Kansas, and the surrounding community. In September 2026,
the hospital notified the Massachusetts Attorney General’s office of a data security incident
affecting the personal information of a small number of Massachusetts residents connected to the
hospital, part of a much larger breach that reached patients across the country.
The underlying incident did not occur on Holton Community Hospital’s own network. Instead, it
originated at Aesto Health (also known as Aesto, LLC), a Birmingham, Alabama-based healthcare
technology company that provides secure data migration, legacy data archiving, and electronic
health record exchange services to numerous hospitals and medical practices, including Holton
Community Hospital. Aesto has stated that an unauthorized third party gained access to a portion
of its Amazon Web Services infrastructure between December 2, 2025, and December 18, 2025, with
the intrusion first identified on or around December 18, 2025.
After the incident was discovered, Aesto engaged outside cybersecurity professionals to
investigate. Following an extensive forensic review and manual document review, Aesto has said it
confirmed on May 26, 2026 that personal and protected health information belonging to patients of
its healthcare-provider clients may have been accessed or acquired without authorization during
that window. Aesto has stated it has no evidence that any of the information has actually been
misused, but is notifying affected individuals out of an abundance of caution.
Because Aesto provides services to dozens of hospitals, clinics, and medical groups around the
country, this single vendor incident grew into one of the largest healthcare data breaches
reported in 2026. Public reporting indicates at least three dozen healthcare-provider clients were
affected, and the incident has reportedly been logged with the U.S. Department of Health and Human
Services’ Office for Civil Rights as impacting more than 9.5 million individuals nationwide,
making it one of the largest confirmed healthcare data breaches of the year. Affected clients
began receiving notice from Aesto on or around June 26, 2026, and in turn began notifying their
own patients over the following months.
The number of people reported affected varies considerably from state to state and provider to
provider, largely because each affected healthcare organization and each state regulator handled
notification independently. Some of Aesto’s healthcare-provider clients have reported tens of
thousands of affected patients apiece, while others, including Holton Community Hospital, have
reported only a small number of affected residents in a given state, such as the three Massachusetts
residents identified in this filing. A small state-specific number like this does not mean the
underlying breach was small; it simply reflects how many people living in that particular state
were affected by a much larger, nationwide incident.
This kind of breach illustrates a broader risk in healthcare: when hospitals rely on outside
vendors to store, migrate, or archive patient records, a single security failure at that vendor can
expose sensitive information belonging to patients of many unrelated healthcare organizations at
once, even though those patients never interacted with the vendor directly.
Because Rural Health Resources of Jackson County, Inc. relied on Aesto for these data services,
any patients whose records passed through Aesto’s systems were within the scope of the exposure,
regardless of whether they had any direct relationship with Aesto itself. Holton Community
Hospital’s Massachusetts filing is one of many state notifications tied to this same underlying
Aesto Health incident, and additional filings may continue to surface as more states report their
own affected resident counts.
When Did This Breach Occur?
According to Aesto Health, unauthorized access to a portion of its Amazon Web Services
infrastructure occurred between December 2, 2025, and December 18, 2025, and the incident was
first identified on or around December 18, 2025. Aesto has said that after an extensive forensic
investigation and manual document review, it confirmed on May 26, 2026 that personal and health
information tied to its healthcare-provider clients, including Holton Community Hospital, may have
been accessed or acquired without authorization during that window. Affected healthcare-provider
clients began receiving notice from Aesto on or around June 26, 2026, and notifications to
individual patients, along with filings with state regulators such as the Massachusetts Attorney
General, have continued in the months since as each affected organization completed its own
notification process.
What Information Was Breached?
Aesto Health has described the information potentially exposed across its affected
healthcare-provider clients as including full names, Social Security numbers, partial dates of
birth, driver’s license numbers, state identification numbers, financial account numbers,
taxpayer identification numbers, health records, medical histories, claims and billing
information, and health insurance information. Aesto has not publicly disclosed a single,
uniform list of exactly which data elements were involved for every affected individual, and the
notice sent to Holton Community Hospital patients did not spell out a complete list specific to
each recipient. Individuals who received a notification letter should review it carefully, since
the exact combination of information exposed can vary from person to person.
What You Can Do
Aesto Health has stated that affected individuals are being offered complimentary credit
monitoring and identity theft protection services for a set period following the incident, and
recipients of a notification letter should follow the enrollment instructions included with their
own notice. In the meantime, affected individuals can take several steps to protect themselves:
- Regularly review bank, credit card, and other financial account statements for unfamiliar
activity.
- Request and review a free copy of your credit report from each of the three major credit
bureaus at annualcreditreport.com.
- Consider placing a fraud alert or a security freeze on your credit file with Equifax,
Experian, and TransUnion.
- Watch for phishing emails, calls, or letters referencing this incident, and never provide
personal information in response to an unsolicited request.
- Report any signs of identity theft or fraud promptly to your state Attorney General and the
Federal Trade Commission.
File a Data Breach Lawsuit Against Holton Community Hospital
If you received a notice that your personal or health information was involved in the Aesto
Health data security incident affecting Holton Community Hospital, you may have legal options
available to you. Businesses and their vendors that collect and store sensitive personal and
health information have a responsibility to keep that data secure, and individuals affected by a
data breach may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.