Lone Star Family Health Center, a federally qualified health center serving patients across Montgomery County, Texas, has notified patients that their personal and health information was involved in a data security incident at one of its business associates. Healthcare organizations that rely on outside vendors to manage patient records have a responsibility to ensure those vendors properly protect sensitive data, and this incident illustrates the risk patients face when a vendor’s systems are compromised.
Lone Star Family Health Center’s Data Breach Investigation
The breach did not originate at Lone Star Family Health Center itself, but at Aesto, LLC d/b/a Aesto Health, a Birmingham, Alabama-based company that provides healthcare data migration and archiving services to Lone Star Family Health Center and dozens of other covered entities nationwide. According to Aesto’s own public notice, an unauthorized third party accessed a portion of Aesto’s Amazon Web Services infrastructure between approximately December 2 and December 18, 2025. Aesto engaged third-party cybersecurity experts to investigate, and on May 26, 2026 confirmed that certain protected health information belonging to patients of its covered-entity clients, including Lone Star Family Health Center, may have been accessed or acquired during that window.
Aesto began notifying its affected covered-entity clients on June 26, 2026, and Lone Star Family Health Center subsequently began notifying its own affected patients, posting a notice on its website directing patients to information about the incident. According to a Texas Attorney General data security breach report, this incident affected the private information of 250,130 individuals connected to Lone Star Family Health Center.
Third-party vendor breaches like this one are an increasingly common way for patient data to be exposed even when the healthcare provider’s own systems are never directly compromised. Because vendors such as Aesto often store or archive years of historical patient records for multiple client organizations at once, a single vendor-side incident can expose a much larger volume of patient data than a breach limited to one provider’s own systems. Healthcare providers remain responsible for verifying that any vendor entrusted with patient data maintains adequate security controls, and patients affected by this kind of incident often have little ability to control how their information was stored or protected by an organization they never directly interacted with.
Data breaches involving Social Security numbers, driver’s license numbers, and detailed medical and health insurance information are particularly valuable to cybercriminals, since this combination of data can be used not only for standard identity theft and fraudulent credit applications but also for medical identity theft, insurance fraud, and fraudulent tax filings. Individuals affected by breaches of this kind are frequently targeted with follow-up phishing attempts that reference the breach itself in order to appear legitimate, making it important for anyone notified of this incident to treat unsolicited calls, texts, or emails referencing Lone Star Family Health Center or Aesto Health with skepticism.
The healthcare sector remains one of the most frequently targeted industries for data breaches, and incidents involving third-party technology vendors have become especially common as more providers outsource data migration, archiving, and record-keeping functions rather than managing them entirely in-house. When a single vendor stores archived or migrated records for dozens of separate healthcare organizations, as Aesto Health did for Lone Star Family Health Center and more than two dozen other covered entities, a single compromise of that vendor’s systems can expose the combined patient populations of every client relying on it, rather than the patient base of any one provider alone. This dynamic has made vendor risk management an increasingly important part of healthcare data security, since a covered entity’s own network defenses offer no protection against a breach occurring entirely within a business associate’s separate infrastructure.
Federal and state breach notification laws generally require that affected individuals be notified within a defined window once the scope of a breach has been confirmed, though the process of forensic investigation, especially one spanning many separate covered-entity clients, can extend the time between an initial intrusion and final notification by several months. In this case, roughly six months passed between the initial unauthorized access in December 2025 and Aesto’s confirmation of the breach’s scope in May 2026, followed by staggered notifications sent out to each affected covered entity’s patients over the following weeks. This kind of delay is common in multi-client vendor breaches and reflects the scale of the forensic review required, not necessarily any wrongdoing by the notifying organizations.
When Did This Breach Occur?
The underlying unauthorized access at Aesto Health is reported to have occurred between approximately December 2, 2025 and December 18, 2025. Aesto confirmed the scope of the incident following a forensic investigation on May 26, 2026, and began notifying its affected covered-entity clients, including Lone Star Family Health Center, on June 26, 2026. Lone Star Family Health Center in turn began notifying its own affected patients afterward, with the Texas Attorney General’s breach report reflecting the incident’s public disclosure.
What Information Was Breached?
The information involved varied by individual but is reported to include full names, Social Security numbers, dates of birth, driver’s license numbers, government-issued ID numbers, financial account numbers, medical information, and health insurance information. Aesto has stated the specific combination of exposed data elements differed from person to person.
What You Can Do
If you received a notice about this breach from Lone Star Family Health Center or Aesto Health, consider taking the following steps:
- Enroll in any free credit monitoring or identity theft protection services offered in the notification letter.
- Place a fraud alert or security freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
- Regularly review your credit reports, bank statements, and health insurance explanation-of-benefits statements for unfamiliar activity.
- Be cautious of unsolicited calls, texts, or emails referencing this breach, as scammers frequently exploit data breach notifications to conduct follow-up phishing attempts.
- Keep a copy of any notice you received, as it may be needed to support a legal claim.
File a Data Breach Lawsuit Against Lone Star Family Health Center
If you were notified that your personal or medical information was compromised in the Lone Star Family Health Center/Aesto Health data breach, you may be entitled to compensation. Organizations that collect and store sensitive patient data, whether directly or through a third-party vendor, are expected to take reasonable steps to protect it, and when that data is exposed, affected individuals can face a lasting risk of identity theft and fraud.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.