Were you recently affected by a data breach?

Tapestry 360 Health Data Breach

Tapestry 360 Health notified patients that a data security incident at its healthcare data vendor, Aesto LLC, exposed names, dates of birth, Social Security numbers, and medical record numbers.

Tapestry 360 Health
Date of Breach: Unauthorized copying occurred between approximately December 2 and December 18, 2025; confirmed by vendor Aesto LLC on May 26, 2026
CAU logo

Who was affected:

Clients of Tapestry 360 Health

Impacted Data:

Full name, date of birth, Social Security number, medical record number

Tapestry 360 Health, a Chicago-based network of community health centers, has notified patients that their protected health information was exposed in a data security incident at Aesto, LLC, a third-party company that provides healthcare data migration and archiving services for Tapestry 360 Health. The incident involved unauthorized copying of a limited amount of patient data stored on Aesto’s network.

Healthcare providers that rely on outside vendors to manage, migrate, or archive patient data have a responsibility to ensure those vendors adequately protect that information, since patients trust their providers with some of the most sensitive information about them. When a vendor’s security fails, the patients whose data was entrusted to that provider still deserve a clear explanation of what happened and meaningful protection going forward.

Tapestry 360 Health’s Data Breach Investigation

According to a notification letter sent to affected patients, Aesto experienced a network security incident on or about December 18, 2025 that impacted a limited portion of its Amazon Web Services infrastructure. Aesto, which provides healthcare data migration and archiving services on behalf of Tapestry 360 Health, launched an investigation with the help of outside cybersecurity professionals following discovery of the incident. After an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026 that between approximately December 2, 2025 and December 18, 2025, an unauthorized actor copied a limited amount of protected health information belonging to Tapestry 360 Health patients that was stored on Aesto’s network.

This incident illustrates a growing risk area in healthcare data security: third-party vendors that handle data migration, archiving, or cloud storage on behalf of medical providers. Even when a healthcare provider itself maintains strong security practices, patient information can still be exposed if a vendor’s infrastructure is compromised, since the vendor often holds copies of the same sensitive records the provider maintains. Cloud infrastructure incidents, like the one described here involving Amazon Web Services systems, have become an increasingly common vector for healthcare data breaches as more providers and their vendors move records to cloud-based storage and archiving systems.

The roughly five-month gap between when the unauthorized copying reportedly occurred (December 2025) and when it was confirmed and disclosed to patients (May 2026) reflects how long a thorough forensic investigation and manual document review can take when an incident is discovered well after the fact, particularly when a third-party vendor and its healthcare-provider client must coordinate together on assessing exactly which patients and records were affected.

Aesto has stated it has no evidence that any of the exposed information has been misused for identity theft or fraud, but Tapestry 360 Health is offering patients a complimentary 24-month credit monitoring membership as a precaution. Given that the exposed information reportedly includes Social Security numbers and medical record numbers, in addition to names and dates of birth, affected patients face a real risk of identity theft and medical fraud and should take the protective steps outlined below.

When Did This Breach Occur?

Aesto detected a network security incident affecting a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Following a forensic investigation, Aesto determined that unauthorized copying of patient data occurred between approximately December 2, 2025 and December 18, 2025. Aesto confirmed on May 26, 2026 that the copied information included protected health information belonging to Tapestry 360 Health patients, after which notification letters were sent to those affected.

What Information Was Breached?

According to the notification letter, the information potentially exposed includes each affected patient’s full name, date of birth, Social Security number, and medical record number. Tapestry 360 Health and Aesto have stated they have no evidence that this information has been misused for identity theft or financial fraud as of the date of the notice.

What You Can Do

If you received a notice from Tapestry 360 Health or Aesto, or believe you may have been affected, consider taking the following steps:

  • Enroll in the complimentary 24-month Single Bureau Credit Monitoring membership offered in the notification letter within 90 days of the letter’s date.
  • Request your free annual credit reports from Equifax, Experian, and TransUnion and review them for unfamiliar accounts or inquiries.
  • Consider placing a fraud alert or security freeze on your credit files with the three major credit bureaus, given that Social Security numbers may have been exposed.
  • Review your health insurance Explanation of Benefits statements for any services you do not recognize.
  • Contact the dedicated response line provided in your notification letter if you have questions about your specific situation.

File a Data Breach Lawsuit Against Tapestry 360 Health

If you were notified that your personal or health information was involved in the Tapestry 360 Health/Aesto data breach, you may have legal options available to you. Healthcare providers and the vendors they rely on are expected to implement reasonable safeguards to protect patient data, and affected individuals may be entitled to compensation when those protections fail.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed as of August 2026
Date of Breach: May 4, 2026 (date of discovery)
Date of Breach: Incident began on or around December 12, 2025
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.