Healthcare
    High
    monitoring
    Updated 1 day ago

    Ellenville Regional Hospital Data Breach

    Key takeaways

    • Reports suggest a potential breach involving Ellenville Regional Hospital.
    • Discovered on September 17, 2026.
    • Possible data exposed: Name, Social Security Number, Date of Birth, Medical Record Number, Hospital Unit, Physician Name.
    • Affects individuals in: Massachusetts.
    • Confirmation level: Confirmed by regulators.

    Breach confirmed

    The Ellenville Regional Hospital breach is confirmed. If you may be affected, add your details below and we will take it from there.

    Detailed summary

    Ellenville Regional Hospital (ERH) announced a data security incident that occurred at its third-party vendor, Aesto, LLC, which provides healthcare data migration and archiving services. The incident at Aesto, LLC, took place on December 18, 2025. ERH learned of the incident on June 26, 2026, and began mailing notification letters to affected individuals on September 16, 2026. The official notice states Aesto had no evidence the information had been misused and that the incident was contained to a limited portion of Aesto’s AWS infrastructure.

    The breach exposed data including names, Social Security numbers, dates of birth, medical record numbers, hospital units, and physician names, though the specific types of information varied by individual. At least 221 Massachusetts residents were affected by the incident. It remains unclear if patients from other states were also affected, as the regulatory notice explicitly identifies only Massachusetts residents. No financial data exposure was confirmed for ERH patients in the official notice.

    Additional details may emerge as investigations progress, and consumers should be aware that notifications can sometimes be delayed. Information regarding potential broader impacts on other Aesto clients has been reported but is not specifically confirmed for Ellenville Regional Hospital patients in the official notice.

    Data possibly involved

    • Name
    • Social Security Number
      Can be used to open fraudulent accounts and file false tax returns
    • Date of Birth
      Often used in combination with other data for identity theft
    • Medical Record Number
    • Hospital Unit
    • Physician Name

    Company Response Timeline

    Response Grade
    C

    Notified consumers within 61–90 days

    Breach Occurred

    Dec 18, 2025

    Company Discovered

    Jun 26, 2026

    Regulator Notified

    Sep 16, 2026

    Consumers Notified

    Sep 16, 2026

    190 days to discover
    82 days to notify consumers

    Breach Verification Status

    Reports Only

    Complete

    Initial dark web reports of potential breach

    Company Confirmed

    Complete

    Company has acknowledged the breach

    Regulator Confirmed

    Current

    Confirmed by regulatory authorities

    Note: Breach verification can take time. Information may evolve as more details become available from companies and regulators.

    Case Status:
    Monitoring

    We're monitoring this situation for developments.

    Were You Affected By This Breach?

    If you are a customer or have received a data breach notification, you may submit your information as part of our ongoing investigation. Submitting your information is free and does not obligate you.

    Were you in the Ellenville Regional Hospital breach? Check your email

    Free scan against known breach datasets. Then remove your info from data-broker sites with Data Shield.

    No signup required. 30-second scan. Your email is only stored if you opt into alerts.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Check Your Risk Level

    Answer a few questions to understand how this breach might affect you

    What should I do?

    Change your passwords

    Update passwords for the affected service and any accounts using the same password

    Enable two-factor authentication

    Add an extra layer of security to your accounts

    Monitor your accounts

    Watch for suspicious activity on your financial and online accounts

    Watch for phishing attempts

    Be cautious of emails or messages claiming to be from the affected company

    Consider a credit freeze

    Prevent unauthorized access to your credit report

    Scan your email for other exposures

    Check whether this address shows up in other known breaches. Free, no account.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Got a notice about this breach?

    Paste it into BreachBrief to see exactly what data was exposed, how serious it is, and what to do next.

    Protect yourself

    Share This Breach Alert

    Help friends and family who might be affected by sharing this breach information

    Are you a law firm investigating this breach?

    Get qualified claimant leads delivered directly to your CRM.

    Related breaches

    Stay informed about breaches like this one

    We'll notify you when new data breaches are reported. Free, no spam. Unsubscribe anytime.

    Free, no spam. Unsubscribe anytime.