
Pittman, Dutton, Hellums, Bradley & Mann, P.C. is investigating a data breach involving Aesto, LLC, which does business as Aesto Health, after the healthcare data migration and archiving vendor reported that patient information may have been accessed or acquired by an unauthorized actor.
Aesto Health issued the notice on behalf of several covered entity clients, including Main Street Medical Services, PLLC. The incident involved Aesto Health’s systems and infrastructure, not necessarily systems maintained directly by Main Street Medical Services.
Patients who received a data breach notice involving Aesto Health or Main Street Medical Services, PLLC may have had sensitive personal and medical information exposed. Those affected may have legal rights and could be entitled to compensation.
Aesto Health provides healthcare data migration and archiving services for covered entity clients. On or around December 18, 2025, Aesto experienced a network security incident that affected a limited portion of its Amazon Web Services infrastructure.
Aesto stated that it acted to contain the incident after detecting unauthorized activity. The company then began an investigation and hired outside cybersecurity experts to help determine whether personal information or protected health information had been involved.
After completing a forensic investigation and manual document review, Aesto confirmed on May 26, 2026, that certain protected health information belonging to patients of covered entity clients may have been accessed and/or acquired by an unauthorized actor.
According to the notice, the unauthorized access may have occurred between approximately December 2, 2025, and December 18, 2025. Aesto began notifying its covered entity clients on or around June 26, 2026. Main Street Medical Services, PLLC was listed as one of the covered entities included in the notice.
The information involved may differ from person to person. Based on Aesto Health’s notice, the information potentially involved may have included:
Aesto stated that Social Security numbers were potentially involved for a limited number of individuals. The company also stated that it had no evidence of identity theft or financial fraud related to the incident at the time notice was issued.
However, the absence of known fraud does not eliminate the risk to affected patients. Sensitive information exposed in a healthcare data breach can remain useful to criminals long after the incident is discovered.
Patients trust healthcare providers and their vendors with some of their most sensitive information. When a vendor such as Aesto Health stores or manages patient data, that vendor must take reasonable steps to protect the information in its care.
Information exposed in a healthcare data breach may be used for identity theft, medical identity theft, insurance fraud, financial fraud, and targeted scam attempts. Criminals may use names, dates of birth, medical details, health insurance information, government identification numbers, or Social Security numbers to create convincing fraud schemes.
For patients of Main Street Medical Services, PLLC, this incident may be confusing because the notice involves a third-party vendor. Even though Aesto Health experienced the security incident, the information at issue may relate to care or services connected to Main Street Medical Services.
If you received a notice related to Aesto Health and Main Street Medical Services, PLLC, you should take the incident seriously. Affected individuals should review the notice carefully, monitor financial accounts, check credit reports, watch for unfamiliar medical bills or insurance claims, and be cautious of suspicious emails, phone calls, or text messages.
You may also want to consider placing a fraud alert or credit freeze with the major credit reporting agencies. These steps can help reduce the risk of new fraudulent accounts being opened in your name.
It is also important to keep a copy of your notification letter and document any time spent, expenses incurred, fraudulent activity, or other problems connected to the breach.
Healthcare vendors that maintain sensitive patient information have a duty to use reasonable safeguards to protect it. When private information is exposed in a data breach, affected individuals may have legal options.
Pittman, Dutton, Hellums, Bradley & Mann, P.C. is investigating the Aesto Health data breach involving patients of Main Street Medical Services, PLLC.
If you received a data breach notification related to Aesto Health or Main Street Medical Services, PLLC, call (205) 322-8880 today for a free consultation.
There are no upfront costs, and you pay nothing unless we recover compensation on your behalf.




Fill out the form below to contact our firm. One of our experienced attorneys is prepared to speak with you. Consultations are free and confidential.