
Pittman, Dutton, Hellums, Bradley & Mann, P.C. is investigating a data breach involving Aesto, LLC, which does business as Aesto Health, after the healthcare data migration and archiving vendor reported that protected health information may have been accessed or acquired by an unauthorized actor.
The notice was issued on behalf of several covered entity clients, including Together Women’s Health Medical Group of Alabama, PC. This means the incident involved Aesto Health’s systems, not necessarily the internal systems of Together Women’s Health Medical Group of Alabama.
Patients who received a data breach notification related to Aesto Health or Together Women’s Health Medical Group of Alabama, PC may have legal rights and could be entitled to compensation.
Aesto Health provides healthcare data migration and archiving services to healthcare providers and other covered entities. On or around December 18, 2025, Aesto discovered unauthorized activity involving a limited portion of its Amazon Web Services infrastructure.
After identifying the incident, Aesto stated that it contained the unauthorized activity and began an investigation. The company also engaged cybersecurity professionals to determine what information may have been involved.
Following a forensic investigation and manual document review, Aesto confirmed on May 26, 2026, that certain protected health information belonging to patients of its covered entity clients may have been accessed and/or acquired by an unauthorized actor between approximately December 2, 2025, and December 18, 2025.
Aesto began notifying affected covered entity clients on or around June 26, 2026. Together Women’s Health Medical Group of Alabama, PC was identified as one of the covered entities included in the notice.
The information involved may vary by individual. According to Aesto Health, the information potentially accessed or acquired may have included:
Aesto stated that Social Security numbers were potentially involved for a limited number of individuals. Aesto also stated that it had no evidence of identity theft or financial fraud related to the incident at the time of the notice.
Even so, the exposure of medical information, health insurance information, government identification numbers, and Social Security numbers can create serious risks for affected patients.
Healthcare vendor breaches can be especially concerning because patients may not recognize the name of the vendor that maintained their information. A patient may have received care from Together Women’s Health Medical Group of Alabama, while their information was stored or handled by Aesto Health as part of a data migration or archiving service.
Medical information and identifying information can be valuable to criminals. Exposed information may be used for identity theft, medical identity theft, financial fraud, insurance fraud, phishing scams, and other forms of misuse.
Unlike a password or debit card number, medical information and Social Security numbers cannot easily be changed. That means affected patients may face long-term risks even if there is no immediate sign of fraud.
If you received a notice involving Aesto Health and Together Women’s Health Medical Group of Alabama, PC, you should carefully review the notice and take steps to protect yourself.
Affected patients may want to monitor credit reports, review bank and financial account statements, watch for suspicious health insurance activity, and be cautious of unexpected emails, text messages, or phone calls asking for personal information.
You may also want to consider placing a fraud alert or credit freeze with the major credit reporting agencies. A credit freeze can help prevent new accounts from being opened in your name without your permission.
You should also keep a copy of the data breach notice and save records of any time spent, money lost, fraudulent activity, or other issues connected to the incident.
Healthcare vendors that collect, store, and maintain sensitive patient information have a responsibility to protect it. When a data breach exposes private information, affected individuals may have legal options.
Pittman, Dutton, Hellums, Bradley & Mann, P.C. is investigating the Aesto Health data breach involving patients of Together Women’s Health Medical Group of Alabama, PC.
If you received a data breach notification related to Aesto Health or Together Women’s Health Medical Group of Alabama, PC, call (205) 322-8880 today for a free consultation.
There are no upfront costs, and you pay nothing unless we recover compensation on your behalf.




Fill out the form below to contact our firm. One of our experienced attorneys is prepared to speak with you. Consultations are free and confidential.