Were you recently affected by a data breach?

Ocracoke Health Center Data Breach

Ocracoke Health Center notified patients that Aesto Health, a healthcare data migration and archiving vendor it works with, experienced a network intrusion that may have exposed patients’ personal and health information.

Ocracoke Health Center
Date of Breach: Unauthorized access occurred December 2-18, 2025; discovered December 18, 2025; confirmed May 26, 2026; notifications began June 26, 2026
CAU logo

Who was affected:

Clients of Ocracoke Health Center

Impacted Data:

Full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, taxpayer identification numbers, other government identification numbers, and for a limited number of individuals, Social Security numbers; the specific elements involved varied by person

Ocracoke Health Center recently notified patients that Aesto, LLC d/b/a Aesto Health, a company that provides healthcare data migration and archiving services on behalf of Ocracoke Health Center and other healthcare providers, experienced a network security incident that may have exposed patients’ personal and protected health information.

Healthcare providers that rely on outside vendors to migrate, store, or archive patient records take on a responsibility to ensure those vendors safeguard that information, and when an incident like this occurs, affected patients deserve clear answers about what happened and what steps they can take next.

Ocracoke Health Center’s Data Breach Investigation

According to Aesto Health’s public notice, the company discovered a network security incident affecting a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Aesto immediately contained the incident and engaged outside cybersecurity experts to determine what personal information, if any, was involved.

After an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026, that between approximately December 2, 2025, and December 18, 2025, protected health information belonging to patients of various healthcare provider clients, including Ocracoke Health Center, stored within Aesto’s network may have been accessed or acquired by an unauthorized party. Aesto began notifying its affected healthcare provider clients on June 26, 2026, so that each provider could in turn notify their own affected patients.

Aesto’s notice states that the information involved varied by individual and could include full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and, for a limited number of individuals, Social Security numbers. The company says it has no evidence of any identity theft or financial fraud related to this incident, though it is notifying affected individuals out of an abundance of caution.

State regulatory filings related to this incident report that approximately 29 Vermont residents were among those affected, a figure that reflects only the state-specific count of residents notified through that state’s own regulatory process. Because Aesto’s breach affected patients across numerous healthcare provider clients nationwide, the total number of individuals affected across all states is likely substantially larger than any single state’s reported figure.

Data breaches involving third-party healthcare data vendors have become an increasingly common and serious concern in recent years, since a single vendor’s systems can hold sensitive records belonging to patients of many separate healthcare providers at once. When a vendor like Aesto experiences an intrusion, the resulting notifications can ripple out to patients of dozens of unrelated clinics, hospitals, and health centers that had no direct role in the vendor’s own security practices, yet whose patients’ data was nonetheless exposed as a result.

The combination of medical information, government identification numbers, and financial account details reported in this incident is particularly sensitive, since this type of data can enable both traditional identity theft and medical identity theft, in which a bad actor uses a victim’s identifying information to fraudulently obtain healthcare services or submit fraudulent insurance claims in the victim’s name.

When Did This Breach Occur?

Aesto Health states that unauthorized access to its network occurred between approximately December 2, 2025, and December 18, 2025, and that it discovered the incident on December 18, 2025. The company confirmed that patient information was involved on May 26, 2026, and began notifying its affected healthcare provider clients, including Ocracoke Health Center, on June 26, 2026.

What Information Was Breached?

Aesto’s notice identifies the following categories of information as potentially involved, noting that the specific elements varied by individual: full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and, for a limited number of individuals, Social Security numbers.

What You Can Do

If you received a letter from Ocracoke Health Center about this breach, consider taking the following steps:

  • Review your explanation of benefits statements for services you do not recognize and follow up with your insurance company or provider about any discrepancies.
  • Monitor your email, phone, and mail for suspicious contact attempts referencing your personal or medical details.
  • Be cautious of unsolicited messages asking you to click a link, download an attachment, or provide additional personal information.
  • Review your financial accounts and credit reports for unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus if you are concerned about identity theft.
  • Keep a copy of your notification letter and any related correspondence in case you need it later.

File a Data Breach Lawsuit Against Ocracoke Health Center

If you received a data breach notification letter from Ocracoke Health Center, or if you believe your personal information was exposed as a result of the Aesto Health incident, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Unauthorized access occurred December 2-18, 2025; discovered December 18, 2025; confirmed May 26, 2026; notifications began June 26, 2026
Date of Breach: Unauthorized access occurred October 8-15, 2025; discovered October 13, 2025; investigation completed August 18, 2026
Date of Breach: Unauthorized access occurred April 24-May 7, 2026; discovered May 7, 2026; investigation completed August 17, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.