Marana Health Center, a community health center serving Marana, Arizona and the surrounding region, has notified patients that their personal and medical information may have been exposed in a data security incident that occurred not at the health center itself, but at one of its third-party vendors, Aesto, LLC. The notification, filed with the New Hampshire Attorney General’s Office, describes an incident that began in December 2025 but was not disclosed to Marana Health Center until six months later.
Healthcare providers routinely rely on outside vendors for services like data migration, archiving, and records management, but that reliance does not relieve the provider of its underlying responsibility to protect the personal and medical information of the patients it serves.
Marana Health Center’s Data Breach Investigation
According to the notification letter filed by Wilson Elser Moskowitz Edelman & Dicker LLP on behalf of Marana Health Center, the health center was notified on or around June 26, 2026, by its vendor Aesto, LLC, of a data security incident that occurred in Aesto’s own network environment on December 18, 2025. Aesto provides healthcare data migration and archiving services, and its investigation determined that between approximately December 2 and December 18, 2025, an unauthorized actor may have accessed or acquired a limited amount of sensitive information belonging to Aesto’s healthcare clients, including Marana Health Center’s patients.
Aesto’s own counsel described the incident as impacting a limited portion of its Amazon Web Services infrastructure. After what the notice describes as an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026, that patient information tied to Marana Health Center had been affected. Marana Health Center began mailing notification letters to potentially impacted individuals on September 23, 2026, roughly nine months after the incident occurred.
This type of vendor-side breach, sometimes called a third-party or supply-chain breach, has become an increasingly common way for patient data to be exposed even when a healthcare provider’s own systems are never directly compromised. Because a single vendor like Aesto can serve numerous healthcare organizations at once, a single security failure in the vendor’s environment can potentially expose patient records belonging to many unrelated providers and their patients simultaneously. This is also why the gap between when a vendor discovers an incident and when it notifies its healthcare clients, and in turn when those clients notify patients, can stretch to many months, as it did here.
The information reportedly compromised in this incident, including Social Security numbers and medical record numbers, is particularly valuable to identity thieves because it can be used both for traditional financial fraud, such as opening new lines of credit, and for medical identity theft, in which a stolen identity is used to obtain healthcare services or prescriptions fraudulently in another person’s name. Medical identity theft can be especially difficult to detect and unwind, since it can result in inaccurate information being added to a victim’s own medical records.
Marana Health Center has indicated it is aware of no reports of related identity theft as of the date of its notice, but that does not mean affected individuals are free of risk going forward. Notification letters for incidents like this one are often the first and only warning patients receive that their information may be circulating outside the organizations they trusted with it.
The delay between a vendor’s discovery of an incident and the eventual notice to patients is not unique to this case. Breach notification laws generally set deadlines that begin running once a covered entity itself learns of an incident, but those clocks often do not start until the vendor has completed its own investigation and formally reported the incident up the chain. For patients, this can mean months pass between the actual unauthorized access and the moment they receive any warning, during which stolen information may already be circulating or being used. It is one of the reasons regulators and consumer advocates have pushed for faster vendor-to-client reporting requirements in recent years, particularly in the healthcare sector where third-party data processors handle records for dozens or even hundreds of provider organizations at once.
When Did This Breach Occur?
The security incident at Aesto, LLC occurred on or about December 18, 2025, with the period of potential unauthorized access spanning from approximately December 2 to December 18, 2025. Aesto did not confirm the scope of impact until May 26, 2026, and did not notify Marana Health Center until June 26, 2026. Marana Health Center then began mailing notification letters to affected individuals on September 23, 2026.
What Information Was Breached?
The notification letter indicates that the information potentially affected varied by individual but may have included full name, date of birth, Social Security number, and medical record number. Marana Health Center reported that a total of fifteen New Hampshire residents were affected by this incident; the total number of patients affected nationwide across all of Aesto’s healthcare clients has not been publicly disclosed.
What You Can Do
- Review the notification letter from Marana Health Center carefully and enroll in any complimentary credit monitoring or identity protection services offered.
- Regularly review your credit reports and financial account statements for unfamiliar activity.
- Consider placing a fraud alert or security freeze with the major credit bureaus.
- Watch for signs of medical identity theft, such as unfamiliar charges from healthcare providers or errors in your own medical records.
- Report any suspected identity theft to the Federal Trade Commission at identitytheft.gov.
File a Data Breach Lawsuit Against Marana Health Center
If you received a notification letter about this incident, you may have legal options available to you. Healthcare providers and the vendors they entrust with patient data are expected to take reasonable steps to safeguard that information, and when a breach occurs, patients can be left facing the burden of monitoring their accounts and medical records for signs of misuse.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.