In 2026, Village Practice Management Company disclosed a data breach that originated from a network security event at Aesto LLC, a vendor providing healthcare data migration and archiving services. The incident occurred around December 18, 2025, when Aesto experienced a security event impacting its Amazon Web Services infrastructure. An investigation confirmed that between December 2, 2025, and December 18, 2025, an unauthorized actor may have accessed protected health information on Aesto's network.
The exposed data includes names, Social Security numbers, dates of birth, medical information, addresses, government IDs, and financial information. Village Practice Management notified affected individuals via U.S. mail. Public reporting indicates that 25,022 residents in Texas and 36 residents in Massachusetts were affected by this incident. The specific number of individuals notified is not separately distinguished from the number affected.
Additional details regarding the official breach notification letter and a direct statement from Village Practice Management are not yet publicly confirmed. State Attorney General filings have not been provided in the available research.