Valley Perinatal Services, LLC, doing business as Advanced Women’s Care, has notified regulators and affected patients of a data security incident that originated at a third-party vendor and exposed sensitive personal and medical information. According to a notice filed with the New Hampshire Attorney General’s office, the breach occurred at Aesto LLC, doing business as Aesto Health, a vendor that stored data on Valley’s behalf, and resulted in the exposure of certain patients’ names, medical record numbers, and Social Security numbers. Healthcare providers that rely on outside vendors to manage patient data still bear responsibility for ensuring that information is properly protected, and when a vendor’s security fails, patients deserve to know exactly what happened and what is being done to help them.
Valley Perinatal Services’s Data Breach Investigation
Valley Perinatal Services, based in Chandler, Arizona and operating as part of the Advanced Women’s Care network of maternal and OB/GYN specialists, learned that its vendor Aesto LLC experienced a network security incident affecting a limited portion of Aesto’s Amazon Web Services infrastructure. According to counsel for Aesto, an unauthorized actor copied certain data stored on Aesto’s network between approximately December 2 and December 18, 2025. Aesto’s investigation, conducted with third-party forensic specialists, concluded on May 26, 2026, and Aesto notified Valley of the impact to its data on June 26, 2026. Valley then reviewed the affected data and determined on July 1, 2026 that the names, medical record numbers, and Social Security numbers of certain New Hampshire residents were included.
This incident illustrates a growing risk in the healthcare industry: patient data is often not stored solely on a provider’s own systems, but is shared with billing companies, cloud infrastructure vendors, scheduling platforms, and other third parties that support day-to-day operations. A security failure at any one of these vendors can expose patient information that the vendor never directly collected from patients themselves, and patients may have no way of knowing which vendors hold their data until a breach notification arrives. Federal and state health privacy laws generally still hold the healthcare provider responsible for notifying patients even when the underlying failure occurred at a vendor’s systems.
The combination of a medical record number and a Social Security number is particularly valuable to identity thieves, since it can enable both traditional financial fraud and medical identity theft, in which a criminal uses a victim’s identity to obtain medical services or prescriptions billed to the victim’s insurance. Medical identity theft can be especially difficult to detect and resolve, since fraudulent charges or treatment records may not appear on a standard credit report and can instead surface only when a patient reviews their insurance explanation of benefits or medical records.
Valley began mailing notice letters to approximately eleven New Hampshire residents on or about August 21, 2026. The sheet monitor’s own tracking also lists Vermont among the states where affected individuals reside, consistent with how multi-state breach notices are often filed separately with each state’s regulator according to that state’s own reporting requirements and thresholds, rather than all at once in a single combined filing.
When Did This Breach Occur?
The underlying security incident at Aesto LLC occurred between approximately December 2, 2025 and December 18, 2025. Aesto confirmed the scope of the incident on May 26, 2026, notified Valley Perinatal Services on June 26, 2026, and Valley determined the specific impact to New Hampshire residents on July 1, 2026. Notification letters began going out to affected individuals on or about August 21, 2026.
What Information Was Breached?
The information involved in this incident includes affected individuals’ names, medical record numbers, and Social Security numbers.
What You Can Do
If you have received a notification letter from Valley Perinatal Services or Advanced Women’s Care, or believe your information may have been affected by this incident, there are several steps you can take to protect yourself:
- Enroll in any free credit monitoring or identity protection services offered in your notification letter.
- Place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
- Review your medical records and insurance explanation of benefits for any unfamiliar claims or services.
- Monitor your financial accounts closely for any unauthorized activity.
- Be cautious of unsolicited emails, calls, or texts asking for personal or financial information, as breach notifications are sometimes followed by phishing attempts.
File a Data Breach Lawsuit Against Valley Perinatal Services
If you were affected by the Valley Perinatal Services data breach, you may be entitled to compensation. Healthcare providers and the vendors they rely on can be held legally accountable when a failure to protect patient data results in harm.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.