Stanislaus County Health Services Agency Data Breach Exposes Patient Health Information

Healthcare data breach illustration
Breach Discovery: May 2026Breach Notification: July 2026

What Happened in the Stanislaus County Health Services Agency Data Breach?

Stanislaus County Health Services Agency recently began sending letters to patients about a data security incident that exposed some of their protected health information. The agency learned that the exposure did not happen inside its own computer systems. Instead, it traced back to Aesto, LLC, a vendor that handles medical record migration and archiving work for SCHSA and other healthcare providers.

According to a notice filed with the California Attorney General’s Office, Aesto detected unusual activity on a portion of its Amazon Web Services infrastructure. The company later determined that unauthorized access to its network occurred between roughly December 2 and December 18, 2025. As a result, an intruder may have viewed or copied protected health information belonging to SCHSA patients that Aesto stored on its systems.

Aesto then launched a forensic investigation to figure out exactly whose data was involved and what information the intruder touched. That review took several months. Aesto confirmed on May 26, 2026 that patient data had indeed been accessed. Because this timeline reflects the vendor’s own confirmation date rather than a fresh public disclosure, this write-up reports on the notification process now reaching Stanislaus County patients directly.

After confirming the exposure, Aesto notified SCHSA of the incident on July 10, 2026. That notice triggered SCHSA’s own duty to inform patients and regulators. The agency subsequently filed its notification with the California Attorney General and began mailing letters to affected individuals. This gap between the intrusion and the notification illustrates how long forensic review can take when a shared vendor coordinates a response across multiple healthcare clients at once.

Who was affected?

The breach affects clients of Stanislaus County Health Services Agency whose records were stored or archived through Aesto’s systems. SCHSA has not publicly disclosed a specific number of affected patients in its filed notice. However, because Aesto provides services to multiple healthcare organizations, the overall scope of this vendor incident likely extends beyond SCHSA alone.

Because SCHSA is a public health agency, its patient population can include individuals across a wide range of ages and backgrounds, including children who received services through county health programs. The notice does not specify whether minors were affected, so any household that has interacted with SCHSA services during the relevant window should treat the notification seriously if received.

What Information Was Potentially Exposed?

The notification letter confirms that each affected patient’s full name was involved in the incident. Beyond that baseline, the letter references additional personal or health information specific to each individual patient. However, the sample notice filed with the state leaves those specific data fields blank rather than listing one universal set of exposed categories for everyone.

Because Aesto specializes in healthcare data migration and archiving, the systems it manages typically hold sensitive medical details alongside basic identifying information. Based on the nature of Aesto’s services, the following categories of information were plausibly at risk for at least some patients:

  • Full names
  • Medical record details and treatment history
  • Other health information specific to each patient’s file
  • Possible identifying details tied to insurance or account records

When medical information ends up in the wrong hands, the risks go beyond typical financial fraud. Criminals can use stolen health details to file fraudulent insurance claims, obtain medical services under someone else’s identity, or combine health data with other stolen information to build a more convincing profile for scams. This type of fraud can be harder to detect than simple credit card misuse because it often surfaces first on a medical bill or insurance statement rather than a bank account.

In addition, because health records often stay valuable to criminals for years after a breach, patients should not assume the risk fades quickly. Even though SCHSA states it has no evidence that anyone has misused the exposed information so far, sensitive medical data can circulate quietly before it appears in fraud attempts. This makes ongoing vigilance more important than a one-time check.

What is the company doing?

Once Aesto confirmed that patient data was affected, it notified SCHSA so the agency could fulfill its own legal obligations to patients and regulators. SCHSA responded by filing formal notice with the California Attorney General’s Office and mailing individual letters to patients whose information may have been involved.

Going forward, SCHSA has indicated that it has found no evidence so far that any exposed information has actually been misused. Nevertheless, the agency is encouraging patients to remain alert and take precautionary steps. Where offered, complimentary credit monitoring or identity protection services are outlined directly in each patient’s individual notification letter.

Verifying Communications From the Agency

Because breach notifications sometimes trigger follow-up scams, patients should treat any message claiming to be from SCHSA or Aesto with caution. Scammers frequently pose as the breached organization, a credit monitoring provider, or even a law firm in an attempt to extract more personal details or payment.

Therefore, patients should verify any follow-up contact using information from their original letter or SCHSA’s own published channels. Avoid clicking links or calling numbers included in unsolicited messages, since a genuine notification will always be traceable back to the agency’s official records.

What Should Affected Individuals Do?

Patients who received a letter from SCHSA or Aesto should take several concrete steps to protect themselves. Because the specific data exposed varies by individual, the letter itself is the best starting point for understanding personal risk.

Review Your Notification Letter Carefully

Start by reading your letter in full to identify which specific data elements were listed as compromised for you personally. This matters because the exposed categories differ from patient to patient, and your protective steps should match your actual risk.

If anything in the letter is unclear, contact SCHSA directly using the phone number or address printed on the letter itself. This ensures you get accurate information without accidentally engaging with a scam attempt disguised as a follow-up notice.

Monitor Your Credit and Consider a Freeze

Because health records sometimes include identifying details that support financial fraud, affected patients should request a free credit report from annualcreditreport.com and review it for unfamiliar accounts. In addition, placing a fraud alert or a full security freeze with Equifax, Experian, and TransUnion adds another layer of protection.

A security freeze restricts new creditors from accessing your credit file, which makes it much harder for a criminal to open new accounts in your name. While a freeze takes a few extra steps when you apply for credit yourself, it offers strong protection during the months following a breach like this one.

Watch for Medical and Insurance Fraud

Because this breach involves a healthcare data vendor, patients should also monitor their medical statements and insurance explanation-of-benefits notices closely. Unfamiliar charges or services you never received could indicate that someone else is using your medical identity.

If you notice anything suspicious, contact your health plan or provider immediately to dispute the charge. Keeping copies of your statements over the coming months will also help if you need to prove fraudulent use later.

Stay Alert for Phishing Attempts

Following any healthcare breach, phishing emails and calls tend to increase as scammers try to capitalize on public awareness of the incident. Be cautious of messages that pressure you to act quickly or that ask you to confirm personal details.

Instead of responding directly, verify the sender through official channels before providing any information. If you ever suspect identity theft, report it to the Federal Trade Commission at identitytheft.gov and to your local law enforcement agency.

Consider Speaking With a Data Breach Attorney

Because a third-party vendor’s security failure led to this exposure, affected patients may have legal options worth exploring. Consulting with an attorney experienced in data breach cases can help you understand whether you qualify for compensation.

Many attorneys offer a free case evaluation, so there is little downside to asking questions about your specific situation. This is especially useful if you later discover fraudulent activity tied to your exposed information.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

View the full list of tracked data breaches →