Ellenville Regional Hospital (ERH) announced a data security incident that occurred at its third-party vendor, Aesto, LLC, which provides healthcare data migration and archiving services. The incident at Aesto, LLC, took place on December 18, 2025. ERH learned of the incident on June 26, 2026, and began mailing notification letters to affected individuals on September 16, 2026. The official notice states Aesto had no evidence the information had been misused and that the incident was contained to a limited portion of Aesto’s AWS infrastructure.
The breach exposed data including names, Social Security numbers, dates of birth, medical record numbers, hospital units, and physician names, though the specific types of information varied by individual. At least 221 Massachusetts residents were affected by the incident. It remains unclear if patients from other states were also affected, as the regulatory notice explicitly identifies only Massachusetts residents. No financial data exposure was confirmed for ERH patients in the official notice.
Additional details may emerge as investigations progress, and consumers should be aware that notifications can sometimes be delayed. Information regarding potential broader impacts on other Aesto clients has been reported but is not specifically confirmed for Ellenville Regional Hospital patients in the official notice.