The breach occurred between December 2 and December 18, 2025, when an unauthorized actor accessed portions of Aesto’s Amazon Web Services infrastructure. While Catalyst Physician Group’s internal systems remained secure, the vendor managed sensitive patient data that included full names and varied medical information. Aesto confirmed the scope of the incident on May 26, 2026, and notification letters were subsequently mailed to affected patients on September 11, 2026.
Catalyst Physician Group is currently offering impacted patients complimentary identity theft protection through IDX, including credit monitoring and a $1,000,000 insurance reimbursement policy. Patients have until December 11, 2026, to enroll in these services. Edelson Lechtzin LLP is now evaluating potential class action claims for those affected by the exposure, citing the risks of medical identity theft and targeted phishing. The firm advises individuals to monitor their financial statements and Explanation of Benefits documents for suspicious activity while considering a credit freeze.





Comments (0)
No comments yet. Be the first!