In a data security incident, Tapestry 360 Health, a Chicago-based network of community health centers, had patient information exposed. The incident occurred at Aesto, LLC, a third-party company providing healthcare data migration and archiving services for Tapestry 360 Health. Unauthorized copying of patient data stored on Aesto's systems took place between approximately December 2 and December 18, 2025. Aesto LLC confirmed the incident on May 26, 2026.
The compromised data types include full names, dates of birth, Social Security numbers, and medical record numbers. The specific number of affected individuals has not been disclosed, and details regarding regulatory notifications or consumer notification dates remain unclear.
Further details, including the precise scope and any official regulatory filings, may emerge as more information becomes publicly available. Patient notifications may also be issued at a later date.