Catalyst Physician Group
bd_8925f3925d1e5282 · schema v1 · pii pii-v2
Full breach record for Catalyst Physician Group →Catalyst Physician Group notified patients of a data breach involving protected health information (PHI) stored by third-party vendor Aesto, LLC. An unauthorized actor accessed data between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. Affected data includes full names and other PHI. The company engaged forensic investigators and is offering identity theft protection services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Sep 11, 2026
Filed
vs. sector median
+27 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- Texas State AGbd_b9a49e9684fcffbf2026-09-15 · +4dVerified
- Massachusetts State AGbd_f402870fea4371242026-09-01 · +10dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 1 (MA), last Sep 15 (TX) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.