Catalyst Physician Group
bd_f402870fea437124 · schema v1 · pii pii-v2
Full breach record for Catalyst Physician Group →Catalyst Physician Group notified patients of a data breach involving their protected health information (PHI). The incident occurred at Aesto, LLC, a third-party vendor providing healthcare data migration and archiving services. An unauthorized actor accessed PHI stored in Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and confirmed the scope of the breach on May 26, 2026, after forensic investigation. Affected data includes full names and other PHI. Catalyst Physician Group is offering complimentary identity theft protection services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Sep 1, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- California State AGbd_8925f3925d1e52822026-09-11 · +10dCandidate
- Texas State AGbd_b9a49e9684fcffbf2026-09-15 · +14dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Sep 1 (MA), last Sep 15 (TX) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.