← Northern Inyo Hospital

2026 Northern Inyo Hospital — Aesto Health archive vendor breach; patient notices (Dec 2025 incident)

2026 Unknown records affected Share on X

Data compromised

PHI/PII held in Aesto archives for Northern Inyo patients may include names, DOB, medical info, driver’s license, financial account numbers, health insurance, government IDs, limited SSNs (elements varied). Hospital aggregate count unpublished — recordsAffected 0.

Technical writeup

Verified downstream hospital notification — ClassAction.org August 24, 2026. Northern Inyo Healthcare District (Northern Inyo Hospital, Bishop, CA) disclosed that a December 2025 security incident at third-party data migration/archiving vendor Aesto Health may have exposed personal and protected health information belonging to patients of Aesto’s clients. A July 31, 2026 notice linked from the hospital and sample Aesto letters describe a Dec 2–18, 2025 AWS window and field list including names, DOB, medical information, driver’s licenses, financial accounts, health insurance, taxpayer/government IDs, and Social Security numbers (varied by individual). Canonical vendor row: aesto-health-aws2026. No facility-specific census published at indexing — recordsAffected 0; companyConfirmed true for the hospital/vendor notice path.

Root cause

Downstream impact from Aesto Health AWS PHI incident (Dec 2–18, 2025); Northern Inyo Healthcare District web notice / patient letters (Aug 2026 reporting)

References