Kaniksu Community Health Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Kaniksu Community Health
Active investigation Data breach · Healthcare Notices mailed Sep 1, 2026

Received a September 2026 breach notice from Kaniksu Community Health?

Dapeer Law, P.A. is investigating a potential class action against Kaniksu Community Health, a community health center serving north Idaho, on behalf of patients whose medical information and Social Security numbers may have been exposed in the unauthorized access to third-party vendor Aesto, LLC disclosed in notice letters filed with the California Attorney General on September 1, 2026.

Submit your claim See what to do No fee unless we recover for you
Breach window
December 18, 2025
Unauthorized access to the Aesto health data platform
Notification delay
About 8 months
Access December 2025, vendor notified Kaniksu June 2026, letters September 2026
Credit monitoring
Not disclosed
Kroll monitoring, term stated in your letter
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Kaniksu Community Health dated September 2026.
  • Your letter offered complimentary identity monitoring through Kroll, including credit monitoring, fraud consultation, and identity theft restoration, with a membership number and an activation deadline printed in the letter.
  • You had patient information, including medical information or your Social Security number, held by Kaniksu Community Health in the Aesto electronic health data platform.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

Kaniksu Community Health disclosed a data security incident in a notice submitted to the California Attorney General on September 1, 2026, with a parallel filing made to the Massachusetts Attorney General. According to the notice, Aesto, LLC, a healthcare data management service provider used by Kaniksu, experienced unauthorized access to its electronic health data platform on or about December 18, 2025. Because Kaniksu patient information was stored within that platform, the incident may have exposed data belonging to Kaniksu patients. Aesto informed Kaniksu of the incident on or about June 26, 2026.

The notice states that Aesto engaged cybersecurity professionals, completed a manual review of the affected files, and continues to assist with mitigation. Kaniksu then opened its own review to determine which of its patients were affected and what information was involved. The filings indicate that the information at issue may have included medical information and Social Security numbers. Kaniksu says it has no evidence that any information has been misused. The Massachusetts filing reports 14 affected residents of that state, and no nationwide total has been released. Letters began going out on September 1, 2026, roughly eight months after the unauthorized access and roughly two months after Aesto notified Kaniksu.

The combination reported here is a serious one. A Social Security number cannot be changed on request and remains usable by identity thieves for years, and medical information carries risks of medical identity theft, fraudulent billing, and insurance fraud that routine credit monitoring does not always detect. Where a health care provider's patient data is exposed through a vendor, our investigation looks at how the provider vetted and monitored that vendor, what contractual and technical safeguards were in place under HIPAA's business associate rules, and whether the eight-month gap between the unauthorized access and patient notification complied with state breach notification deadlines.

California Attorney General Massachusetts Attorney General Third-Party Vendor Breach Aesto, LLC Social Security Numbers Medical Information Kroll Identity Monitoring Healthcare Data Breach
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard your Kaniksu Community Health notice letter. The letter contains your Kroll membership number, the activation deadline, and the list of information categories involved in your case, all of which are important evidence if you decide to participate in a lawsuit.

2

Enroll in the free Kroll identity monitoring

Enroll in the Kroll identity monitoring offered in your letter before the activation deadline printed there, using the membership number Kaniksu provided. Enrollment is available at enroll.krollmonitoring.com, and Kaniksu has set up a dedicated line at (844) 958-8978, open 9:00 a.m. to 6:30 p.m. Eastern, Monday through Friday. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because a Social Security number may have been involved, also place a free security freeze with Equifax, Experian, and TransUnion, order your free credit reports at AnnualCreditReport.com, and consider requesting an Identity Protection PIN from the IRS to guard against fraudulent tax filings. Because medical information may also have been involved, review the explanation of benefits statements from your health plan for services you did not receive, and request a copy of your medical file if you see anything unfamiliar.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your Kaniksu Community Health notice, explain your options, and advise whether you may be eligible to pursue claims under Idaho, California, Massachusetts, or other state data breach and consumer protection laws.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

December 18, 2025 Passed
Unauthorized access to the Aesto, LLC electronic health data platform holding Kaniksu patient information
June 26, 2026 Passed
Aesto informs Kaniksu Community Health of the incident, Kaniksu opens its own review
September 1, 2026 Passed
Notice filed with the California Attorney General and the Massachusetts Attorney General, letters mailed to patients
See your letter Active
Deadline to activate the complimentary Kroll identity monitoring membership
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, fraudulent accounts or loans opened in your name, fraudulent tax filings, medical identity theft and fraudulent billing, insurance fraud, credit freeze and restoration costs, and the time you spent responding to the incident, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Kaniksu Community Health to implement stronger safeguards over the patient medical information and Social Security numbers it holds, including tighter vendor vetting and contractual security requirements, encryption at rest, data minimization, and prompt notification of affected patients in the event of a future incident.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Kaniksu Community Health. What should I do? +

Keep your Kaniksu Community Health notice letter and the Kroll membership number it contains, activate the complimentary identity monitoring before the deadline printed in your letter, place a free security freeze with Equifax, Experian, and TransUnion, order your free credit reports at AnnualCreditReport.com, review your medical, insurance, and financial statements for unfamiliar activity, consider requesting an Identity Protection PIN from the IRS, document any time or money you spend responding to the incident, and consider speaking with a data breach attorney. If you experience identity theft, report it to the FTC at ftc.gov/idtheft or (877) 438-4338 and file a police report, keeping a copy for your records.

Am I eligible to join a class action against Kaniksu Community Health? +

Patients who received a Kaniksu Community Health notice letter dated September 2026 are the most direct candidates. Eligibility for any legal claim will also depend on your state of residence, the categories of your information that were involved, and any documented losses or out-of-pocket expenses. Because the filings report that medical information and Social Security numbers may have been involved, recipients may have stronger claims than in incidents limited to contact information. A free case review can help you understand your options.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

According to the notices filed with the California and Massachusetts Attorneys General, the information that may have been involved includes medical information and Social Security numbers. The public filings do not itemize the exposure patient by patient, and not every recipient's letter will list every category. Your individual letter is the most reliable source for exactly what was involved in your case, so we recommend reviewing it carefully and saving a copy.

Did Kaniksu Community Health offer free credit monitoring? +

Yes. Kaniksu Community Health arranged complimentary identity monitoring through Kroll, which the notice describes as including credit monitoring, fraud consultation, and identity theft restoration services. The term of the membership and the activation deadline are printed in your individual letter rather than in the public filing. Enrollment is at enroll.krollmonitoring.com using the membership number in your letter, and Kaniksu's dedicated line is (844) 958-8978. Enrolling does not waive your right to pursue legal action.

How many people were affected by the Kaniksu Community Health breach? +

The Massachusetts Attorney General filing reports 14 affected residents of that state. That figure covers Massachusetts only. Kaniksu Community Health has not publicly disclosed how many patients were notified nationwide, and because the incident occurred at a third-party vendor, other Aesto customers may have been affected as well. This page will be updated if additional information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

Kaniksu Community Health filed the breach notice with the California Attorney General and with the Massachusetts Attorney General, and both PDFs can be downloaded from the links in the Sources & References section below. If you cannot locate your individual letter, Dapeer Law can help you obtain a copy as part of a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Kaniksu Community Health, Kroll, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 1, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Berkeley Research Group Data Breach Lawsuit Investigation

Next
Next

The Florida Aquarium Data Breach Lawsuit Investigation