Were you recently affected by a data breach?

Lone Star Family Health Center Data Breach

Lone Star Family Health Center notified patients that their personal and health information was exposed in a security incident at Aesto Health, a third-party data migration vendor. Sensitive data including Social Security numbers and medical records may have been accessed.

Lone Star Family Health Center
Date of Breach: December 2-18, 2025 (incident window at third-party vendor Aesto Health)
CAU logo

Who was affected:

Clients of Lone Star Family Health Center

Impacted Data:

Names, Social Security numbers, dates of birth, driver’s license numbers, government-issued ID numbers, financial account numbers, medical information, and health insurance information

Lone Star Family Health Center, a federally qualified health center serving patients across Montgomery County, Texas, has notified patients that their personal and health information was involved in a data security incident at one of its business associates. Healthcare organizations that rely on outside vendors to manage patient records have a responsibility to ensure those vendors properly protect sensitive data, and this incident illustrates the risk patients face when a vendor’s systems are compromised.

Lone Star Family Health Center’s Data Breach Investigation

The breach did not originate at Lone Star Family Health Center itself, but at Aesto, LLC d/b/a Aesto Health, a Birmingham, Alabama-based company that provides healthcare data migration and archiving services to Lone Star Family Health Center and dozens of other covered entities nationwide. According to Aesto’s own public notice, an unauthorized third party accessed a portion of Aesto’s Amazon Web Services infrastructure between approximately December 2 and December 18, 2025. Aesto engaged third-party cybersecurity experts to investigate, and on May 26, 2026 confirmed that certain protected health information belonging to patients of its covered-entity clients, including Lone Star Family Health Center, may have been accessed or acquired during that window.

Aesto began notifying its affected covered-entity clients on June 26, 2026, and Lone Star Family Health Center subsequently began notifying its own affected patients, posting a notice on its website directing patients to information about the incident. According to a Texas Attorney General data security breach report, this incident affected the private information of 250,130 individuals connected to Lone Star Family Health Center.

Third-party vendor breaches like this one are an increasingly common way for patient data to be exposed even when the healthcare provider’s own systems are never directly compromised. Because vendors such as Aesto often store or archive years of historical patient records for multiple client organizations at once, a single vendor-side incident can expose a much larger volume of patient data than a breach limited to one provider’s own systems. Healthcare providers remain responsible for verifying that any vendor entrusted with patient data maintains adequate security controls, and patients affected by this kind of incident often have little ability to control how their information was stored or protected by an organization they never directly interacted with.

Data breaches involving Social Security numbers, driver’s license numbers, and detailed medical and health insurance information are particularly valuable to cybercriminals, since this combination of data can be used not only for standard identity theft and fraudulent credit applications but also for medical identity theft, insurance fraud, and fraudulent tax filings. Individuals affected by breaches of this kind are frequently targeted with follow-up phishing attempts that reference the breach itself in order to appear legitimate, making it important for anyone notified of this incident to treat unsolicited calls, texts, or emails referencing Lone Star Family Health Center or Aesto Health with skepticism.

The healthcare sector remains one of the most frequently targeted industries for data breaches, and incidents involving third-party technology vendors have become especially common as more providers outsource data migration, archiving, and record-keeping functions rather than managing them entirely in-house. When a single vendor stores archived or migrated records for dozens of separate healthcare organizations, as Aesto Health did for Lone Star Family Health Center and more than two dozen other covered entities, a single compromise of that vendor’s systems can expose the combined patient populations of every client relying on it, rather than the patient base of any one provider alone. This dynamic has made vendor risk management an increasingly important part of healthcare data security, since a covered entity’s own network defenses offer no protection against a breach occurring entirely within a business associate’s separate infrastructure.

Federal and state breach notification laws generally require that affected individuals be notified within a defined window once the scope of a breach has been confirmed, though the process of forensic investigation, especially one spanning many separate covered-entity clients, can extend the time between an initial intrusion and final notification by several months. In this case, roughly six months passed between the initial unauthorized access in December 2025 and Aesto’s confirmation of the breach’s scope in May 2026, followed by staggered notifications sent out to each affected covered entity’s patients over the following weeks. This kind of delay is common in multi-client vendor breaches and reflects the scale of the forensic review required, not necessarily any wrongdoing by the notifying organizations.

When Did This Breach Occur?

The underlying unauthorized access at Aesto Health is reported to have occurred between approximately December 2, 2025 and December 18, 2025. Aesto confirmed the scope of the incident following a forensic investigation on May 26, 2026, and began notifying its affected covered-entity clients, including Lone Star Family Health Center, on June 26, 2026. Lone Star Family Health Center in turn began notifying its own affected patients afterward, with the Texas Attorney General’s breach report reflecting the incident’s public disclosure.

What Information Was Breached?

The information involved varied by individual but is reported to include full names, Social Security numbers, dates of birth, driver’s license numbers, government-issued ID numbers, financial account numbers, medical information, and health insurance information. Aesto has stated the specific combination of exposed data elements differed from person to person.

What You Can Do

If you received a notice about this breach from Lone Star Family Health Center or Aesto Health, consider taking the following steps:

  • Enroll in any free credit monitoring or identity theft protection services offered in the notification letter.
  • Place a fraud alert or security freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
  • Regularly review your credit reports, bank statements, and health insurance explanation-of-benefits statements for unfamiliar activity.
  • Be cautious of unsolicited calls, texts, or emails referencing this breach, as scammers frequently exploit data breach notifications to conduct follow-up phishing attempts.
  • Keep a copy of any notice you received, as it may be needed to support a legal claim.

File a Data Breach Lawsuit Against Lone Star Family Health Center

If you were notified that your personal or medical information was compromised in the Lone Star Family Health Center/Aesto Health data breach, you may be entitled to compensation. Organizations that collect and store sensitive patient data, whether directly or through a third-party vendor, are expected to take reasonable steps to protect it, and when that data is exposed, affected individuals can face a lasting risk of identity theft and fraud.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Reported to Vermont AGO on September 10, 2026
Date of Breach: January 26, 2026 - February 3, 2026
Date of Breach: Claimed September 10, 2026 (unconfirmed by the company)
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.