Aesto Health, which operates as Murfreesboro Medical Clinic, confirmed a data breach that exposed patient medical and personal information, including Social Security numbers. The company filed notifications with attorneys general in Washington, California, and Vermont in 2026. The exact number of affected patients has not been publicly disclosed. Affected individuals should monitor credit reports, consider a credit freeze, and watch for medical identity theft signs immediately.
| Company | Aesto, LLC d/b/a Aesto Health |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Full Names, Medical Treatment and Diagnosis Records, Health Insurance Information, Patient Account or Medical Record Numbers, Social Security Numbers, Dates of Birth, Contact Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unspecified/Unauthorized Access |
| Regulators Notified | California Attorney General, Vermont Attorney General, Washington State Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Aesto Health Data Breach?
Aesto, LLC, doing business as Aesto Health and operating as Murfreesboro Medical Clinic, has filed formal data breach notifications with multiple state regulators. These filings confirm that unauthorized parties accessed sensitive patient information. The Aesto Health data breach has now triggered notification requirements in several states, including Washington, California, and Vermont.
According to the notification filed with the Washington State Attorney General, the healthcare provider determined that patient data had been compromised. The exact date the breach was discovered has not been publicly disclosed. However, the company notified the Washington regulator in August 2026, which is when the public first learned about this incident.
As a result of this discovery, the organization appears to have launched an internal review process. The filing itself does not detail the specific attack method used by the intruders. Because the notification focuses on regulatory compliance rather than technical detail, many aspects of the incident, including how attackers first gained entry, remain unclear at this time.
In addition, the notification does not specify whether the intrusion involved ransomware, a phishing scheme, or another form of unauthorized access. What is confirmed is that Aesto Health treated the event seriously enough to notify regulators in multiple jurisdictions. This pattern suggests the exposed data affected patients living across several states, not just one region.
Who was affected?
The individuals affected by this breach appear to be patients of Murfreesboro Medical Clinic, which operates under the Aesto Health name. Because healthcare providers typically hold detailed records on every patient they treat, this incident likely touches people who received medical care, tests, or treatment through the clinic.
The total number of affected individuals has not been publicly disclosed. Regulatory filings in Washington, California, and Vermont indicate that patients in multiple states received notification letters. This means the breach was not limited to a single geographic area or a small local population.
Because medical clinics often serve patients of all ages, it is possible that minors are among those affected. Parents and guardians who have brought children to Murfreesboro Medical Clinic should watch for notification letters as well. Additionally, anyone who received care through Aesto Health in recent years could be part of the exposed population, even if they no longer live in the area.
What Information Was Potentially Exposed?
Healthcare data breaches typically involve highly sensitive categories of personal and medical information. While the notification filed with regulators does not itemize every specific data field, breaches of this type at medical clinics commonly involve the following categories.
- Full names
- Medical treatment and diagnosis records
- Health insurance information
- Patient account or medical record numbers
- Social Security numbers
- Dates of birth
- Contact information, including addresses and phone numbers
This combination of medical and personal identifying information creates serious risk for affected patients. For example, criminals can use Social Security numbers combined with dates of birth to open new credit accounts or file fraudulent tax returns. Because medical identity theft is harder to detect than standard financial fraud, victims may not notice a problem until they receive a suspicious bill or collection notice.
Moreover, exposed medical records can lead to consequences beyond typical identity theft. Fraudsters sometimes use stolen health insurance details to obtain medical services or prescriptions under someone else’s name. This can corrupt a victim’s own medical history, which creates confusion during future treatment and can even affect insurance coverage decisions down the road.
What is the company doing?
Aesto Health responded to the breach by filing official notifications with state attorneys general, including Washington, California, and Vermont. This step fulfills legal requirements that healthcare organizations notify regulators and affected individuals after a confirmed data compromise. The company also filed formal notification with the California Attorney General and the Vermont Attorney General.
These filings suggest the organization has acknowledged the incident and taken steps toward compliance with breach notification laws. However, the publicly available filing does not describe additional remediation steps, such as system upgrades or new security controls. It also does not confirm whether affected patients are being offered free credit monitoring or identity protection services.
Because multiple filings were submitted across different months in 2026, it appears the investigation and notification process unfolded in phases. This could mean the organization identified additional affected individuals or states over time. Patients should watch for an official letter, since notification letters typically include specifics about any protective services offered.
What Should Affected Individuals Do?
Monitor Your Credit Reports Closely
Anyone who received care at Murfreesboro Medical Clinic should request a copy of their credit report right away. You can obtain a free report from each of the three major credit bureaus through AnnualCreditReport.com. Reviewing these reports regularly helps you catch unauthorized accounts before they cause lasting damage.
In addition, consider setting up ongoing credit monitoring if it is offered by the company. If no free service is provided, several low-cost monitoring tools can alert you to new inquiries or accounts opened in your name. Because Social Security numbers may have been exposed, this step is especially important for long-term protection.
Consider a Fraud Alert or Credit Freeze
Given that Social Security numbers were likely involved in this breach, placing a fraud alert on your credit file is a smart precaution. A fraud alert requires lenders to verify your identity before opening new credit in your name. This makes it significantly harder for criminals to use stolen information successfully.
For even stronger protection, you can request a credit freeze with each bureau. This step blocks access to your credit file entirely until you choose to lift it. While a freeze requires a bit more effort to manage, it offers one of the most effective defenses against identity theft.
Watch for Signs of Medical Identity Theft
Because medical records and insurance details may have been exposed, patients should carefully review any insurance statements or medical bills they receive. Look for treatments, prescriptions, or services you do not recognize. These could indicate someone else is using your identity to obtain care.
If you notice anything unusual, contact your insurance provider immediately. You should also request a copy of your medical records to check for inaccuracies. Correcting fraudulent entries early can prevent complications during future medical treatment.
Stay Alert for Phishing Attempts
After a healthcare data breach, scammers often send fake emails or text messages pretending to be from the affected organization. These messages may ask you to click a link or share personal details. Because attackers now have real patient information, their messages can appear convincing.
Therefore, avoid clicking links in unexpected messages, even if they reference Aesto Health or Murfreesboro Medical Clinic by name. Instead, contact the organization directly using a verified phone number. This simple habit can prevent a second wave of fraud following the original breach.
Consult a Data Breach Attorney
If you received a notification letter about this breach, you may want to speak with a data breach attorney. An attorney can help you understand whether you qualify for compensation through a class action or individual claim. Many offer free consultations, so there is little risk in asking questions.
Because healthcare breaches often involve highly sensitive data, courts have sometimes awarded damages to affected patients. A qualified attorney can review your specific situation and explain your legal options. This is especially worth considering if you experience direct financial or medical harm as a result of this breach.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
Official data breach notification from California Attorney General
View the public data breach notification listing from Vermont Attorney General
Official data breach notification report (PDF) from Washington State Attorney General
