Northern Inyo Hospital Patient Data Exposed via Aesto Health Breach
Sensitive medical records and Social Security numbers were compromised through a third-party vendor vulnerability in December 2025.
Northern Inyo Hospital has confirmed a data breach that exposed sensitive patient information through a third-party service provider. The incident highlights the persistent security risks healthcare facilities face when outsourcing data management to external vendors.
The breach stems from a security incident at Aesto Health, a company specializing in data migration and archiving. Unauthorized access occurred between December 2 and December 18, 2025, exposing a wide array of Protected Health Information (PHI) and personally identifiable information (PII). Compromised data includes patient names, dates of birth, medical information, and Social Security numbers. Additionally, driver's license numbers, financial account numbers, health insurance details, taxpayer identification numbers, and other government ID numbers were potentially exposed.
The Third-Party Vulnerability
Northern Inyo Hospital, located in Bishop, California, relied on Aesto Health for critical data archiving and migration services. This incident follows a pattern where healthcare providers experience breaches not through internal systems, but via the vulnerabilities of their business associates. In the healthcare sector, third-party vendors often maintain deep access to patient databases to facilitate technical transitions, creating a single point of failure that can impact multiple healthcare clients simultaneously.
Industry Implications
This breach underscores the systemic risk associated with third-party vendor management in the medical sector. When PHI is compromised, patients face long-term risks of identity theft and medical fraud. These issues are often more difficult to resolve than traditional financial fraud because medical histories are permanent and cannot be "reset" like a credit card number.
For healthcare administrators, the incident serves as a reminder that regulatory compliance and patient privacy obligations extend to the security practices of every vendor in their supply chain. The reliance on external specialists for data migration creates a critical dependency that requires rigorous auditing and continuous monitoring to prevent unauthorized access.
Next Steps
While the nature of the exposed data has been identified, the total number of individuals impacted by the Northern Inyo Hospital breach has not been publicly disclosed. Patients are encouraged to monitor their financial accounts and medical statements for unauthorized activity. Further scrutiny is expected as legal monitoring sites and class action trackers continue to follow the fallout of the Aesto Health security failure.