databreaches.net 8/13/2026, 3:40:56 PM · external

QVMC alerts patients following Aesto vendor data breach

CyberSIXT Evidence Panel Source marked as original reporting

QUINCY Valley Medical Center (QVMC) informed patients about a security incident involving Aesto, a third-party vendor responsible for archiving patient data, which was disclosed on July 7, 2026. Letters to patients were sent on August 5, adhering to a 30-day notification requirement. QVMC clarified that it did not experience a breach but was cautious due to Aesto's incident.

Aesto reported a security incident on December 18, 2025, where unauthorized access to patient information occurred, including sensitive data like Social Security numbers, but found no evidence of misuse. Aesto notified clients on June 26, 2026, raising concerns about timely communication. For further inquiries, patients are encouraged to contact a dedicated response line.

View full article

Article by CyberSIXT