Catalyst Physician Group Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Catalyst Physician Group
Active investigation Data breach · Healthcare Notices mailed Sep 11, 2026

Received a September 2026 breach notice from Catalyst Physician Group?

Dapeer Law, P.A. is investigating a potential class action against Catalyst Physician Group, a physician practice group, on behalf of patients whose protected health information may have been exposed in a network security incident affecting the Amazon Web Services environment of its technology vendor, Aesto.

Submit your claim See what to do No fee unless we recover for you
Breach window
Dec 2 to 18, 2025
Unauthorized access to vendor AWS environment
Notification delay
About 3.5 months
Discovered May 2026, notices Sep 2026
Credit monitoring
Free IDX services
Enrollment deadline Dec 11, 2026, term not stated
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Catalyst Physician Group dated September 2026.
  • Your letter offered enrollment in complimentary IDX identity-theft protection services, including credit monitoring and CyberScan dark-web monitoring.
  • You received care from, or had protected health information held by, Catalyst Physician Group, whose vendor Aesto hosted that data in its Amazon Web Services environment.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

According to a notice filed with the California Attorney General, Aesto, a technology vendor to Catalyst Physician Group, experienced a network security incident that affected a limited portion of its Amazon Web Services infrastructure. Aesto reports that an unauthorized actor was able to access the environment between December 2 and December 18, 2025. The activity was discovered on May 26, 2026.

Aesto states that it engaged external cybersecurity professionals, conducted a forensic investigation, and completed a manual review of the affected documents to determine what information was involved. Catalyst Physician Group began mailing notice letters on September 11, 2026, roughly three and a half months after discovery and about nine months after the access window closed. The notice describes a limited amount of protected health information as accessible and identifies full name among the data elements, without itemizing the remaining categories. Aesto reports no evidence that any of the information has been misused as of the date of the notice.

Catalyst Physician Group is offering impacted individuals complimentary identity-theft protection services through IDX, which include credit monitoring, CyberScan dark-web monitoring, up to $1,000,000 in insurance reimbursement coverage, and fully managed identity-theft recovery assistance. Because the data at issue is health information held by a medical provider, notice recipients should watch for medical identity theft as well as financial fraud, including unfamiliar Explanation of Benefits statements and claims for care they did not receive.

Protected health information Third-party vendor incident Cloud environment compromise California Attorney General filing Medical identity theft risk
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the enrollment code for the IDX identity-protection services and is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free IDX identity-protection services

Enroll in the IDX services offered in your letter before the December 11, 2026 deadline, either at app.idx.us/account-creation/protect or by calling 1-866-200-0884. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because this incident involved health information, also review your Explanation of Benefits statements and request a copy of your medical records for entries you do not recognize.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options under HIPAA-related state privacy and breach notification laws, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

Dec 2 to 18, 2025 Passed
Unauthorized access to Aesto's Amazon Web Services environment
May 26, 2026 Passed
Aesto discovers the security incident
May to Sep 2026 Passed
Forensic investigation and manual document review completed
Sep 11, 2026 Passed
Notice filed with the California Attorney General, letters mailed
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. The IDX enrollment window closes on December 11, 2026. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, medical-claim fraud, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Catalyst Physician Group and its technology vendors to implement stronger data security practices for patient health information going forward.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Catalyst Physician Group. What should I do? +

Keep your letter, including the enrollment code. Enroll in the free IDX identity-protection services before the December 11, 2026 deadline, either online at app.idx.us/account-creation/protect or by calling 1-866-200-0884. Review your account statements and Explanation of Benefits forms for activity you do not recognize, request your free annual credit reports, and consider a fraud alert or a credit freeze if anything looks suspicious. You can also speak with a data breach attorney at no cost about your legal options.

Am I eligible to join a class action against Catalyst Physician Group? +

Patients who received a notice letter from Catalyst Physician Group about this incident are the most likely candidates. Eligibility can also depend on your state of residence, the categories of information involved in your particular letter, and whether you have documented out-of-pocket losses or time spent responding to fraud. A free case review is the fastest way to find out where you stand.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The notice states that a limited amount of protected health information stored in Aesto's Amazon Web Services environment was accessible, and it identifies full name among the affected data elements. The remaining categories are not itemized in the public notice, so the specific information involved may vary by individual. Check your own letter, which lists the data elements that applied to you.

Did Catalyst Physician Group offer free credit monitoring? +

Yes. Catalyst Physician Group is offering complimentary identity-theft protection services through IDX, which include credit monitoring, CyberScan dark-web monitoring, up to $1,000,000 in insurance reimbursement coverage, and fully managed identity-theft recovery assistance. The enrollment window closes on December 11, 2026. The length of the monitoring term is not stated in the public notice. Enrolling does not waive your right to pursue a claim.

How many people were affected by the Catalyst Physician Group breach? +

The total number of individuals affected has not been publicly disclosed as of September 15, 2026. The notice filed with the California Attorney General does not give a figure. This page will be updated as more information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

The notice was filed with the California Attorney General and can be downloaded from that office's data breach notification portal. If you cannot locate a copy, Dapeer Law can help you obtain one during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Catalyst Physician Group, IDX, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 11, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Cornerstone Staffing Solutions Data Breach Lawsuit Investigation

Next
Next

zHealth Data Breach Lawsuit Investigation