Skip to main content
Jump to a category page

Johnson Memorial Health Services, a Minnesota healthcare provider, has notified patients that their Social Security numbers and medical records were exposed in a breach at Aesto, LLC — the same data-management vendor breach that has now affected 9.5 million people at hospitals nationwide.

Johnson Memorial Health Services, based in Dawson, Minnesota, reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation on September 4, 2026, confirming that patient information was exposed in a data security incident at Aesto, LLC, a Birmingham, Alabama company that provides healthcare data migration and archiving services. According to Aesto’s own notice letter, the incident occurred between approximately December 2 and December 18, 2025, and Aesto confirmed on May 26, 2026 that patient information had been accessed. Johnson Memorial’s own filing confirms Social Security numbers and medical records were involved.

Source: Massachusetts Office of Consumer Affairs and Business Regulation filing 2026-1508 (reported 09/04/2026); Aesto, LLC’s own Notice of Data Breach letter, sent on behalf of Johnson Memorial Health Services.

Part of a 9.5 Million-Person Nationwide Vendor Breach

Johnson Memorial is one of numerous hospitals and healthcare providers across the country affected by Aesto’s data security incident. According to Aesto’s own reporting to the U.S. Department of Health and Human Services, the breach affects approximately 9,540,683 individuals nationwide — one of the largest healthcare data breaches reported this year. Aesto’s letter states that the exposed information may include a patient’s full name along with additional data elements specific to each covered entity, which for Johnson Memorial’s patients included Social Security numbers and medical records.

Source: HIPAA Journal and BleepingComputer reporting on Aesto Health’s breach disclosure and its submission to the HHS Office for Civil Rights breach portal (9,540,683 individuals).

What Johnson Memorial Is Offering

According to Aesto’s notice letter, sent through Kroll on Johnson Memorial’s behalf, affected individuals are being offered a complimentary membership in Experian’s IdentityWorks Credit 3B monitoring product, along with identity restoration support. The letter also states that this notification was not delayed by law enforcement.

Source: Aesto, LLC’s Notice of Data Breach letter, sent on behalf of Johnson Memorial Health Services.

A Long Chain From Breach to Notice

Aesto’s intrusion window closed on December 18, 2025. Aesto’s covered-entity notification wave to its hospital clients began around June 26, 2026 — roughly six months later. Johnson Memorial then reported its own consumer notice on September 4, 2026. Measured from the original incident to that notice, the gap runs to roughly 260 days.

Do You Have Legal Options?

Healthcare providers have a legal duty to ensure that the vendors they trust with patient data secure it properly and disclose incidents without unreasonable delay — and that duty doesn’t disappear just because a third-party vendor was the one that got breached.

If you received a notice letter naming Johnson Memorial Health Services and Aesto, contact Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

FAQ

Who is affected by the Johnson Memorial data breach?

Patients of Johnson Memorial Health Services in Dawson, Minnesota whose information was stored on the network of Aesto, LLC, a third-party data migration and archiving vendor. Johnson Memorial reported the breach to Massachusetts regulators on September 4, 2026.

What information was exposed?

Johnson Memorial’s own regulatory filing confirms Social Security numbers and medical records were involved.

Is this the same breach affecting other hospitals?

Yes. Aesto, LLC’s data security incident affected numerous hospitals and healthcare providers across the country, totaling approximately 9.5 million people according to Aesto’s own reporting to federal regulators. Johnson Memorial Health Services is one of the affected covered entities.

What is Johnson Memorial offering affected patients?

According to the notice letter, affected individuals are being offered a complimentary membership in Experian’s IdentityWorks Credit 3B monitoring product, along with identity restoration support.

Has a lawsuit already been filed?

Yes. Multiple lawsuits have been filed against Aesto, LLC in the Northern District of Alabama over this breach, including Jackson v. Aesto, Sibthorpe v. Aesto, Nguyen v. Aesto, McDaniel v. Aesto, Chalmers v. Aesto, and Doe v. Aesto.

Do I have a legal claim?

Healthcare providers have a legal duty to ensure that the vendors handling patient data secure it properly and disclose incidents without unreasonable delay. If you received a notice letter naming Johnson Memorial Health Services and Aesto, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now