Nebraska Orthopaedic Center reported a data breach connected to a December 2025 security incident at Aesto Health, a third-party healthcare data migration and archiving company. Aesto said the incident affected a limited portion of its Amazon Web Services infrastructure and that information stored in its network may have been viewed or acquired by an unauthorized individual between December 2 and December 18, 2025. Aesto posted a breach notice on June 24, 2026, and began notifying affected clients on June 26, 2026.
The information potentially involved Nebraska Orthopaedic Center patients' names, dates of birth, medical information, health insurance information, financial account numbers, Social Security numbers, taxpayer identification numbers, government identification numbers, and driver's license numbers. The number of individuals affected specifically through Nebraska Orthopaedic Center has not been publicly disclosed. Aesto reported the incident to the Vermont Attorney General's Office on July 31, 2026.
The available materials do not state when Nebraska Orthopaedic Center discovered the incident or when it directly notified consumers. Further details about the entity-level impact and notification timeline may be disclosed in later notices or filings.