Catalyst Physician Group Data Breach Lawsuit Investigation
Received a September 2026 breach notice from Catalyst Physician Group?
Dapeer Law, P.A. is investigating a potential class action against Catalyst Physician Group, a physician practice group, on behalf of patients whose protected health information may have been exposed in a network security incident affecting the Amazon Web Services environment of its technology vendor, Aesto.
Who may qualify
You may be eligible to participate in a class action if any of the following applies:
- You received a data breach notification letter from Catalyst Physician Group dated September 2026.
- Your letter offered enrollment in complimentary IDX identity-theft protection services, including credit monitoring and CyberScan dark-web monitoring.
- You received care from, or had protected health information held by, Catalyst Physician Group, whose vendor Aesto hosted that data in its Amazon Web Services environment.
- No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
- Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.
Not sure if you qualify?
Send us your notice, we'll confirm your eligibility at no cost.
What happened
According to a notice filed with the California Attorney General, Aesto, a technology vendor to Catalyst Physician Group, experienced a network security incident that affected a limited portion of its Amazon Web Services infrastructure. Aesto reports that an unauthorized actor was able to access the environment between December 2 and December 18, 2025. The activity was discovered on May 26, 2026.
Aesto states that it engaged external cybersecurity professionals, conducted a forensic investigation, and completed a manual review of the affected documents to determine what information was involved. Catalyst Physician Group began mailing notice letters on September 11, 2026, roughly three and a half months after discovery and about nine months after the access window closed. The notice describes a limited amount of protected health information as accessible and identifies full name among the data elements, without itemizing the remaining categories. Aesto reports no evidence that any of the information has been misused as of the date of the notice.
Catalyst Physician Group is offering impacted individuals complimentary identity-theft protection services through IDX, which include credit monitoring, CyberScan dark-web monitoring, up to $1,000,000 in insurance reimbursement coverage, and fully managed identity-theft recovery assistance. Because the data at issue is health information held by a medical provider, notice recipients should watch for medical identity theft as well as financial fraud, including unfamiliar Explanation of Benefits statements and claims for care they did not receive.
What to do if you received a letter
Keep your notice letter
Do not discard it. Your letter contains the enrollment code for the IDX identity-protection services and is important evidence if you decide to participate in a lawsuit.
Enroll in the free IDX identity-protection services
Enroll in the IDX services offered in your letter before the December 11, 2026 deadline, either at app.idx.us/account-creation/protect or by calling 1-866-200-0884. Accepting this benefit does not waive your right to pursue legal action.
Place a fraud alert or credit freeze
Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because this incident involved health information, also review your Explanation of Benefits statements and request a copy of your medical records for entries you do not recognize.
Speak with a data breach attorney
Consultations with Dapeer Law are free and confidential. We'll review your notice, explain your options under HIPAA-related state privacy and breach notification laws, and advise whether you may be eligible to join a class action.
Submit your notice for a free review
Two minutes online. A licensed attorney reviews every submission.
Breach timeline
Compensation you may be entitled to
Out-of-pocket expenses
Credit freezes, identity restoration services, and other costs incurred responding to the breach.
Time spent monitoring
Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.
Identity theft & fraud losses
Unreimbursed funds stolen from accounts, unauthorized credit lines, medical-claim fraud, or tax refund fraud tied to the breach.
Statutory damages
Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.
Injunctive relief
Court orders requiring Catalyst Physician Group and its technology vendors to implement stronger data security practices for patient health information going forward.
Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.
Common questions
I received a data breach letter from Catalyst Physician Group. What should I do? +
Keep your letter, including the enrollment code. Enroll in the free IDX identity-protection services before the December 11, 2026 deadline, either online at app.idx.us/account-creation/protect or by calling 1-866-200-0884. Review your account statements and Explanation of Benefits forms for activity you do not recognize, request your free annual credit reports, and consider a fraud alert or a credit freeze if anything looks suspicious. You can also speak with a data breach attorney at no cost about your legal options.
Am I eligible to join a class action against Catalyst Physician Group? +
Patients who received a notice letter from Catalyst Physician Group about this incident are the most likely candidates. Eligibility can also depend on your state of residence, the categories of information involved in your particular letter, and whether you have documented out-of-pocket losses or time spent responding to fraud. A free case review is the fastest way to find out where you stand.
How much money could I receive from a class action lawsuit? +
Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.
What personal information was exposed in the breach? +
The notice states that a limited amount of protected health information stored in Aesto's Amazon Web Services environment was accessible, and it identifies full name among the affected data elements. The remaining categories are not itemized in the public notice, so the specific information involved may vary by individual. Check your own letter, which lists the data elements that applied to you.
Did Catalyst Physician Group offer free credit monitoring? +
Yes. Catalyst Physician Group is offering complimentary identity-theft protection services through IDX, which include credit monitoring, CyberScan dark-web monitoring, up to $1,000,000 in insurance reimbursement coverage, and fully managed identity-theft recovery assistance. The enrollment window closes on December 11, 2026. The length of the monitoring term is not stated in the public notice. Enrolling does not waive your right to pursue a claim.
How many people were affected by the Catalyst Physician Group breach? +
The total number of individuals affected has not been publicly disclosed as of September 15, 2026. The notice filed with the California Attorney General does not give a figure. This page will be updated as more information becomes available.
Is there a deadline to take legal action? +
Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.
How do I get a copy of the official breach notice? +
The notice was filed with the California Attorney General and can be downloaded from that office's data breach notification portal. If you cannot locate a copy, Dapeer Law can help you obtain one during a free consultation.
Sources & references
- Official breach notice filing · California Attorney General, Catalyst Physician Group and Aesto breach notice (PDF)
- Credit bureau freezes · Equifax · Experian · TransUnion
- Free weekly credit reports · AnnualCreditReport.com
- Identity theft recovery guide · FTC IdentityTheft.gov
Don't let the deadline decide for you. Submit your claim today.
You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.