← Quincy Valley Medical Center

2026 Quincy Valley Medical Center — Aesto Health archive vendor breach; patient letters (Dec 2025 incident)

2026 Unknown records affected Share on X

Data compromised

Protected health information stored in Aesto archives for Grant County Public Hospital District 2 patients per Aesto notice: names, DOB, medical info, driver’s license, financial account numbers, health insurance, ITIN/other gov IDs, limited SSNs (elements varied). QVMC aggregate count not published — recordsAffected 0.

Technical writeup

Verified downstream hospital notification — August 2026. Quincy Valley Medical Center (Grant County Public Hospital District 2, Quincy, WA) posted that it did not experience a direct security incident; rather, archived patient data hosted by vendor Aesto Health was involved in Aesto’s December 2025 AWS breach (canonical row: aesto-health-aws2026). QVMC was notified July 7, 2026 and authorized patient letters mailed August 5 within HIPAA’s 60-day window from discovery. Aesto’s notice describes PHI categories including names, DOB, medical information, driver’s licenses, limited financial account numbers, health insurance, government IDs, and limited SSNs. QVMC directed questions to [email protected]. No facility-specific patient census was published at indexing — recordsAffected 0.

Root cause

Downstream impact from Aesto Health AWS PHI incident (Dec 2–18, 2025); QVMC notified July 7, 2026; patient letters authorized Aug 5, 2026

References