OB-GYN South Data Breach Exposes Social Security Numbers and Medical Records

Healthcare data breach illustration
Breach Discovery: December 2025Breach Notification: Not Publicly Disclosed

What Happened in the OB-GYN South Data Breach?

OB-GYN South, a women’s health provider serving the Birmingham, Alabama area, has told patients that their personal information was caught up in a breach at one of its outside vendors. The OB-GYN South data breach did not originate on the practice’s own network. Instead, it traces back to Aesto Health, a Birmingham-based company that handles data exchange and archiving services for healthcare organizations.

According to the notice, intruders gained unauthorized access to Aesto Health’s network starting in early December 2025. The intrusion itself was pinpointed to December 18, 2025, though the activity apparently continued for a stretch of time before it was caught. Because Aesto Health serves many healthcare clients, the fallout reached patients well beyond its own direct customer base.

Once the incident came to light, Aesto Health launched a forensic investigation to determine exactly whose data had been touched. That review eventually confirmed that records tied to OB-GYN South patients were part of what got exposed. As a result, OB-GYN South had to wait on its vendor’s findings before it could notify its own patients.

This kind of layered discovery process is common in vendor breaches. A single compromised vendor can serve dozens of unrelated healthcare providers, so identifying every affected organization takes time. That delay is a normal feature of how these incidents unfold, not necessarily a sign that anyone dropped the ball.

Who was affected?

The people affected are patients of OB-GYN South, a practice connected to the Together Women’s Health network. Because this is a women’s health clinic, the exposed population likely includes patients across a range of ages, including those who received prenatal, gynecological, or other reproductive health services.

The exact number of patients affected by this breach has not been publicly disclosed. However, because the underlying incident occurred at a vendor that supports multiple healthcare organizations, other unrelated practices’ patients were also caught up in the same Aesto Health breach, separate from OB-GYN South’s patient population.

Patients should not assume they are safe simply because they had no direct dealings with Aesto Health. Since the vendor handled records on behalf of OB-GYN South, anyone whose information passed through that system could be affected, regardless of how limited their direct contact with the vendor was.

What Information Was Potentially Exposed?

The notice describes a fairly broad set of personal and medical data connected to this incident. This combination of data types is more dangerous than a breach involving just contact information, because it gives criminals multiple ways to impersonate victims.

  • Full names
  • Dates of birth
  • Medical information
  • Driver’s license numbers
  • Financial account numbers
  • Social Security numbers

When Social Security numbers are exposed alongside driver’s license numbers and financial account details, criminals gain nearly everything they need to open new credit lines, file fraudulent tax returns, or take over existing accounts. This is a far more serious combination than names and email addresses alone.

In addition, the presence of medical information raises the risk of medical identity theft. Someone could use a stolen identity to obtain prescriptions, medical equipment, or even treatment under another person’s name, which can corrupt medical records and create billing disputes that take years to untangle.

What is the company doing?

Once Aesto Health discovered the intrusion, it worked to determine which of its healthcare clients, including OB-GYN South, had patient data involved. This forensic review process allowed OB-GYN South to confirm which patients needed to be notified.

After that determination was made, OB-GYN South sent notification letters by mail to affected patients. This step fulfills the practice’s obligations under healthcare privacy laws, which require covered entities to inform patients when their protected health information has been compromised through a business associate.

Going forward, incidents like this one typically prompt healthcare providers to review the safeguards required in their vendor contracts. Because HIPAA obligates covered entities to maintain business associate agreements governing data protection, this breach may also lead OB-GYN South to reassess how its vendors secure sensitive records.

What Should Affected Individuals Do?

Monitor Your Credit Reports and Financial Accounts

Anyone who received a notification letter should start checking their credit reports regularly. Look for new accounts, unfamiliar inquiries, or any changes you don’t recognize.

You can request a free credit report from each of the three major bureaus. Because Social Security numbers were involved in this breach, ongoing monitoring for months or even years afterward is a smart precaution, since stolen data can surface on the black market long after the initial incident.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers, driver’s license numbers, and financial account numbers were all reportedly exposed, placing a fraud alert or credit freeze is a reasonable next step. A freeze blocks new creditors from accessing your credit file entirely, which makes it much harder for someone to open accounts in your name.

To set this up, contact each of the three major credit bureaus directly. While a freeze takes a bit of extra effort when you need new credit yourself, it offers strong protection against the kind of identity theft this breach makes possible.

Watch for Medical Identity Theft and Insurance Fraud

Because medical information was part of this breach, patients should also review any insurance statements or explanation-of-benefits notices closely. If you see services listed that you never received, that could be a sign your medical identity has been misused.

Contact your insurance provider immediately if anything looks unfamiliar. Correcting a corrupted medical record can be difficult, so catching problems early gives you the best chance of limiting the damage.

Stay Alert for Phishing Attempts

Scammers often use news of a breach to craft convincing phishing emails or phone calls. They may pose as OB-GYN South, Aesto Health, or even a credit bureau to try to trick victims into handing over more information.

Never click links or share personal details in response to unsolicited messages referencing this breach. Instead, go directly to the official website or phone number for any organization that contacts you, and verify the request independently before responding.

Keep Records and Know Your Legal Options

Save your notification letter along with any evidence of suspicious activity tied to your accounts. This documentation could become important if you later decide to pursue compensation for harm caused by the breach.

Because this breach involved highly sensitive data like Social Security numbers and medical records, affected patients may have legal options worth exploring. Speaking with a data breach attorney for a free case evaluation can help you understand whether you qualify to join a claim.



Related Data Breaches

Check other recent data breach notifications →