Together Women’s Health Data Breach Investigation
The Together Women’s Health Medical Group PC data incident was reported in connection with a network security event involving healthcare data vendor Aesto Health. Aesto’s public notice states that protected health information belonging to patients of covered entity clients may have been accessed or acquired without authorization. Strauss Borrelli PLLC is investigating the incident and its potential impact on patients. Individuals who received a notice can fill out the secure contact form on this page to verify whether they may qualify to pursue a claim.
Key Facts at a Glance
- Entity Involved: Together Women’s Health Medical Group PC (Healthcare)
- Incident Type: Third-party network security incident involving possible unauthorized access
- Date of Incident: December 2, 2025 to December 18, 2025
- Discovery Date: December 18, 2025
- Official Notice Date: June 26, 2026
- Exposed Information: Names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, taxpayer identification numbers, government identification numbers, and Social Security numbers
- Affected Population: Not publicly stated; under investigation
What Happened?
The incident involving Together Women’s Health Medical Group PC was reported in connection with Aesto Health, a company that provides healthcare data migration and archiving services to covered entity clients. According to Aesto’s public notice, unauthorized activity affected a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Aesto reported that it contained the activity and began an investigation with outside cybersecurity professionals.
Following a forensic investigation and manual document review, Aesto said it confirmed on May 26, 2026, that an unauthorized actor may have accessed or acquired certain protected health information stored within its network between December 2 and December 18. Aesto stated that it began notifying covered entity clients whose patient information appeared in the potentially affected files on June 26. The notice also stated that Aesto had not found evidence of identity theft or financial fraud related to the event at the time of publication. That statement does not eliminate the possibility of future misuse.
What Information Was Exposed?
According to Aesto’s notice, the information potentially involved varied by person. Reported data categories included names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government identification numbers, and Social Security numbers. Aesto stated that Social Security numbers were potentially involved for a limited number of people.
Because medical, insurance, identity, and financial information may have been combined, affected patients could face risks such as medical identity theft, fraudulent patient billing, false insurance claims, prescription-related inquiries, or scams impersonating a healthcare provider or insurer. Receiving a notice does not necessarily mean every listed data element was involved for that recipient.
What Should You Do Next?
- Review the notice carefully: Determine which information may have been involved and keep the notice with your records. Direct incident questions to Aesto’s response line at 833-918-8060 and reference engagement number B167683.
- Check your credit reports: Obtain free reports from the nationwide credit bureaus through AnnualCreditReport.com. Look for unfamiliar accounts, credit inquiries, addresses, or collection activity that could indicate identity misuse.
- Consider a credit freeze or fraud alert: A security freeze can restrict access to your credit file, while a fraud alert asks potential creditors to take additional identity-verification steps. Contact each credit bureau when placing a freeze.
- Monitor medical and insurance records: Review explanation-of-benefits statements, patient portals, prescription histories, and provider bills for services you did not receive. Promptly dispute suspicious entries with the provider and insurer.
- Be alert for healthcare phishing: Treat unexpected insurance-verification calls, prescription inquiries, billing demands, and messages requesting account credentials as suspicious. Contact the provider or insurer through a verified phone number rather than replying or clicking a link.
Your Legal Rights
People whose personal or protected health information was potentially involved may have rights under applicable state privacy, consumer-protection, data-security, and breach-notification laws. The rights available in any particular situation depend on factors such as residency, the information involved, the relationship between the healthcare provider and its vendor, and whether the incident caused documented losses or other legally recognized harm.
Affected individuals should preserve their notification letter, suspicious messages, credit reports, medical bills, insurance statements, and records of time or expenses spent responding to the incident. An attorney can review these materials, explain possible options, and assess whether an individual may be eligible to participate in litigation. This general information is not individualized legal advice, and no outcome can be guaranteed.
Why Hire Strauss Borrelli PLLC?
Strauss Borrelli PLLC evaluates cybersecurity and privacy incidents involving sensitive medical, insurance, financial, and identity information. The firm can investigate the circumstances surrounding a reported incident, assess potential legal rights, and help affected individuals understand whether they may qualify to pursue a claim. A confidential consultation can provide information tailored to the facts without obligating a person to take legal action.
If you believe you may have been affected by the Together Women's Health Medical Group PC data breach:
We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.










