Were you recently affected by a data breach?

Nebraska Orthopaedic Center Data Breach

Nebraska Orthopaedic Center has disclosed that patient information was exposed after a security incident at third-party vendor Aesto Health. Compromised data may include Social Security numbers, driver’s license numbers, and medical information. Attorneys are investigating whether affected patients can pursue a class action lawsuit.

Nebraska Orthopaedic Center
Date of Breach: December 2, 2025 - December 18, 2025 (detected December 18, 2025)
CAU logo

Who was affected:

Clients of Nebraska Orthopaedic Center

Impacted Data:

Full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, government identification numbers, and Social Security numbers (for a limited number of individuals)

Nebraska Orthopaedic Center, a Lincoln, Nebraska-based orthopedic physician group, has notified patients that their personal and health information may have been exposed after a security incident affecting a third-party vendor. Healthcare providers that rely on outside companies to store, migrate, or archive patient records are still responsible for making sure that information stays protected, and a breach at any point in that chain can leave patients vulnerable to identity theft and fraud.

Nebraska Orthopaedic Center’s Data Breach Investigation

Attorneys working with Class Action U are investigating whether Nebraska Orthopaedic Center can be held legally responsible for a data security incident that exposed sensitive patient information. The investigation centers on Nebraska Orthopaedic Center’s relationship with Aesto, LLC, doing business as Aesto Health, a company that provides healthcare data migration and archiving services to physician practices, hospitals, and other covered entities across the country. Nebraska Orthopaedic Center was one of roughly two dozen covered entity clients whose patient records were stored on Aesto’s network at the time of the incident.

According to a notice posted by Aesto Health, the company detected unauthorized activity affecting a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Aesto says it immediately contained the intrusion and hired outside cybersecurity specialists to determine what happened and whose information may have been involved. After what the company describes as an extensive forensic investigation and a manual document review, Aesto confirmed on May 26, 2026 that an unauthorized actor had accessed or acquired protected health information belonging to patients of its covered entity clients, including patients of Nebraska Orthopaedic Center, sometime between approximately December 2, 2025 and December 18, 2025.

Aesto began formally notifying its covered entity clients on June 26, 2026, roughly seven months after the intrusion is said to have first occurred and about a month after the forensic review confirmed that patient data had actually been compromised. Nebraska Orthopaedic Center has not, as of this writing, publicly disclosed the exact number of patients affected, and attorneys note that vendor-side breaches like this one can take considerably longer to fully investigate and disclose than a breach that occurs directly on a healthcare provider’s own network, since the forensic work must first determine which of the vendor’s many clients had which specific patient files stored on the compromised systems.

Healthcare providers increasingly rely on third-party vendors for tasks like records migration, cloud storage, and long-term archiving, particularly during practice mergers, acquisitions, or system upgrades, which is exactly the kind of service Aesto Health markets to physician groups. That efficiency comes with a tradeoff: patients who have never directly interacted with the vendor, and who may not even know their provider uses one, can still have their most sensitive information exposed if the vendor’s own security controls fail. Federal law under HIPAA still holds the covered healthcare entity, not just its vendor, responsible for ensuring that any business associate handling patient data maintains reasonable safeguards, which is part of why plaintiffs’ attorneys are examining Nebraska Orthopaedic Center’s own vendor oversight practices as part of this investigation, not solely Aesto’s security posture.

Healthcare data breaches remain especially attractive targets for cybercriminals because medical records are unusually difficult for victims to change or cancel compared with a credit card number or even a Social Security number. A stolen medical record can combine a patient’s identity, insurance details, and treatment history in a single file, giving criminals everything needed to file fraudulent insurance claims, obtain prescription drugs under someone else’s name, or open new lines of credit. That combination is part of why healthcare has consistently ranked among the most frequently breached industries in recent years, and why state and federal regulators have pushed for stricter vendor-management and breach-notification requirements industry-wide.

For patients of Nebraska Orthopaedic Center who received a notice about this incident, or who otherwise believe their information may have been part of the files stored on Aesto’s compromised systems, the practical next steps are the same as with any healthcare data breach: confirm exactly what categories of information were involved, monitor financial and medical accounts closely, and consider the protective steps outlined below. Attorneys working with Class Action U are continuing to gather information from affected patients as part of the ongoing investigation into how the breach occurred and whether Nebraska Orthopaedic Center and Aesto Health met their legal obligations to protect patient data.

When Did This Breach Occur?

Aesto Health says the unauthorized access to its systems occurred between approximately December 2, 2025 and December 18, 2025, with the intrusion detected on or about December 18, 2025. After an extended forensic investigation, Aesto confirmed on May 26, 2026 that patient information had actually been accessed or acquired during that window. The company began notifying its covered entity clients, including Nebraska Orthopaedic Center, on June 26, 2026. Nebraska Orthopaedic Center’s own notice to patients followed after that date, and this investigation was first published on August 12, 2026.

What Information Was Breached?

According to Aesto Health’s notice, the information that may have been exposed varied from patient to patient but could include full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government-issued identification numbers, and, for a more limited number of patients, Social Security numbers. Nebraska Orthopaedic Center has not publicly disclosed the specific number of its own patients affected by the incident. Because this breach involved a data migration and archiving vendor rather than a single point-of-sale system or website, the exact combination of data exposed can differ depending on which records the vendor had stored for a given patient at the time of the intrusion.

What You Can Do

Patients of Nebraska Orthopaedic Center who are concerned about this breach can take several steps to help protect themselves. Carefully review the notice you received for the specific categories of information involved in your case, since not every affected patient had the same data exposed. Consider placing a fraud alert or credit freeze with the three major credit bureaus, monitor your bank and credit card statements for unfamiliar activity, and review your health insurance Explanation of Benefits statements for services you do not recognize, which can be a sign of medical identity theft. If Nebraska Orthopaedic Center or Aesto Health offered complimentary credit monitoring or identity protection services as part of the notice, consider enrolling. Report any suspicious account activity to your financial institutions and insurer promptly, and keep a copy of your breach notice, since it can serve as evidence if you later decide to pursue legal action.

File a Data Breach Lawsuit Against Nebraska Orthopaedic Center

If you received a notice about the Nebraska Orthopaedic Center data breach, or otherwise believe your information was exposed through Aesto Health’s compromised systems, you may have legal options. Attorneys are investigating whether Nebraska Orthopaedic Center and Aesto Health took reasonable steps to protect the personal and health information entrusted to them, and whether affected patients can pursue compensation for the harm caused by this incident.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: June 8-12, 2026
Date of Breach: December 2, 2025 - December 18, 2025 (detected December 18, 2025)
Date of Breach: Breached in June 2026; publicly reported August 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.