In section Releases

Law Firm Investigates Catalyst Physician Group Data Breach

Roughly 9.5 million individuals across various healthcare providers may have had their sensitive information compromised following a security incident at Aesto, LLC, a third-party vendor for Texas-based Catalyst Physician Group. National law firm Edelson Lechtzin LLP has launched an investigation into the exposure of protected health information.

Law Firm Investigates Catalyst Physician Group Data Breach

The breach occurred between December 2 and December 18, 2025, when an unauthorized actor accessed portions of Aesto’s Amazon Web Services infrastructure. While Catalyst Physician Group’s internal systems remained secure, the vendor managed sensitive patient data that included full names and varied medical information. Aesto confirmed the scope of the incident on May 26, 2026, and notification letters were subsequently mailed to affected patients on September 11, 2026.

Catalyst Physician Group is currently offering impacted patients complimentary identity theft protection through IDX, including credit monitoring and a $1,000,000 insurance reimbursement policy. Patients have until December 11, 2026, to enroll in these services. Edelson Lechtzin LLP is now evaluating potential class action claims for those affected by the exposure, citing the risks of medical identity theft and targeted phishing. The firm advises individuals to monitor their financial statements and Explanation of Benefits documents for suspicious activity while considering a credit freeze.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!