Catalyst Physician Group Data Breach Exposes Protected Health Information

Published: 14 September 2026
Healthcare data breach illustration
Breach Discovery: December 2025Breach Notification: September 2026

A December 2025 network intrusion at vendor Aesto, LLC exposed protected health information belonging to Catalyst Physician Group patients, including names and medical details. Aesto found no evidence of misuse, but notified patients in September 2026. Affected individuals should enroll in the free IDX identity protection offered before the December 11, 2026 deadline and monitor medical and financial statements closely.

CompanyCatalyst Physician Group
IndustryHealthcare
Data Types ExposedFull Name, Protected Health Information, Medical Treatment Details
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Network Access
Regulators NotifiedCalifornia Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Catalyst Physician Group Data Breach?

Catalyst Physician Group has notified patients about a data security incident that exposed protected health information. The breach did not occur inside Catalyst’s own systems. Instead, it happened at Aesto, LLC, a third-party vendor that handles healthcare data migration and archiving services for the practice.

According to the notification, unauthorized access to Aesto’s network occurred in December 2025. Aesto later determined that an unauthorized actor accessed or acquired data between December 2 and December 18, 2025. The intrusion specifically affected a portion of Aesto’s Amazon Web Services infrastructure, where patient records tied to Catalyst Physician Group were stored.

Once Aesto discovered the issue, it launched an investigation. As a result, the company brought in outside cybersecurity specialists to determine the scope of the incident. This process included forensic analysis and a manual review of affected files. That work was extensive, and it took several months before Aesto could confirm, on May 26, 2026, which individuals and data elements were involved.

Notably, Aesto says it has found no evidence that any stolen information has actually been misused. However, because sensitive health data was involved, the company chose to notify affected patients out of caution. Catalyst Physician Group then began sending written notices to patients in September 2026.

Who was affected?

The individuals affected by this breach are patients whose protected health information was stored by Aesto on behalf of Catalyst Physician Group. Because Aesto provides data migration and archiving services, the exposed records may include information collected over an extended period of patient care.

The exact number of affected individuals has not been publicly disclosed. It is also not clear from available information whether the breach affected patients in a single state or across a wider geographic area. Given that Catalyst Physician Group is a physician practice, the affected population likely includes both current and former patients.

There is no indication in the notification that minors were specifically targeted or excluded. Therefore, families who received care through Catalyst Physician Group should assume any patient in the household, including children, could potentially be included in the exposure.

What Information Was Potentially Exposed?

The notification letter identifies patient names as one confirmed data element involved in the breach. In addition, the letter references other categories of protected health information that varied by individual, though the exact combination was not spelled out for every recipient.

Based on the notification, the following categories of information were potentially exposed:

  • Full name
  • Protected health information related to care at Catalyst Physician Group
  • Additional personal details that varied by individual, as referenced in the notification’s enclosed information

Because this was healthcare data, the exposure carries real risk even without evidence of misuse so far. Medical information can be used to commit medical identity theft, where a criminal uses someone else’s identity to obtain treatment, prescriptions, or medical equipment. This type of fraud can be difficult to detect and can even affect a victim’s own medical records.

In addition, exposed health information is often paired with names and other identifying details, which can support broader identity theft schemes. For example, scammers frequently use stolen medical details to craft convincing phishing messages that appear to come from a legitimate healthcare provider. As a result, affected patients should treat any unexpected medical-related communication with suspicion.

What is the company doing?

After discovering the incident, Aesto worked closely with external cybersecurity professionals to investigate the scope of the breach. This included a forensic review of the affected systems and a manual document review to identify exactly whose information was involved. Aesto also secured the affected Amazon Web Services infrastructure to prevent further unauthorized access.

Catalyst Physician Group filed a formal notification with the California Attorney General in connection with this incident. In addition to notifying regulators, the company is offering affected individuals a complimentary membership in identity theft protection services through IDX. This includes credit and CyberScan monitoring, a $1,000,000 insurance reimbursement policy, and fully managed identity theft recovery services.

Affected patients can enroll using an individual enrollment code provided in their notification letter. The deadline to enroll in the free IDX protection is December 11, 2026. Catalyst Physician Group has also set up a dedicated response line for questions about the incident.

What Should Affected Individuals Do?

Enroll in the Free Identity Protection Services

Because Catalyst Physician Group is offering complimentary IDX identity theft protection, affected individuals should take advantage of this benefit. The service includes credit monitoring, CyberScan monitoring, and recovery support if identity theft occurs. Enrollment requires the unique code included in the notification letter.

To enroll, patients can call 1-866-200-0884, visit the IDX enrollment website, or scan the QR code provided in their letter. Since the enrollment deadline is December 11, 2026, affected individuals should not delay. Waiting too long could mean missing out on this free protection entirely.

Monitor Your Medical and Financial Records

Because protected health information was involved, patients should review any explanation of benefits statements from their health insurer closely. This helps catch unfamiliar treatments, prescriptions, or providers billed under your name. If anything looks unfamiliar, contact your insurer immediately.

In addition to medical records, it’s wise to review bank and credit card statements regularly. Medical identity theft can sometimes lead to financial fraud as well, especially if additional personal details were exposed. Consistent monitoring makes it easier to catch fraud early, before it causes lasting damage.

Consider a Fraud Alert or Credit Freeze

Even though Aesto reports no evidence of misuse, placing a fraud alert can add an extra layer of protection. A fraud alert requires creditors to verify your identity before opening new accounts in your name. You can place one for free with Equifax, TransUnion, or Experian, and it will apply across all three bureaus.

For stronger protection, consider a credit freeze, which restricts access to your credit file entirely. This makes it much harder for identity thieves to open new accounts using your information. Keep in mind that you will need to lift the freeze temporarily whenever you apply for credit yourself.

Stay Alert for Phishing Attempts

Because your name and health information may have been exposed, scammers could use these details to craft convincing phishing emails, texts, or phone calls. These messages might reference your medical provider or appear to come from Catalyst Physician Group directly. Always verify the sender before clicking links or sharing information.

If you receive a suspicious message referencing this breach, contact Catalyst Physician Group directly using a verified phone number rather than any number provided in the message. This simple step can prevent you from accidentally giving scammers even more personal information. When in doubt, it’s always safer to hang up and call back using an official number.

Know Your Legal Options

If your protected health information was exposed in this breach, you may have legal options available to you. Many affected individuals choose to consult a data breach attorney for a free case evaluation to understand their rights. An attorney can help determine whether you qualify for compensation related to this incident.

Because deadlines for legal claims can vary and are often time-sensitive, it’s wise to act sooner rather than later. Gathering your notification letter and any evidence of related fraud can help support a potential claim. Taking this step costs nothing upfront in most cases and can provide valuable peace of mind.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

View the full list of tracked data breaches →