Almeida Law Group is investigating a data breach at Kaniksu Community Health. If you were affected, contact Almeida Law Group.
About Kaniksu Community Health
Kaniksu Community Health is a Federally Qualified Health Center (FQHC) headquartered in Sandpoint, Idaho, with clinic locations in Bonners Ferry, Priest River, and Ponderay. It serves over 25,000 residents of Bonner and Boundary counties and provides integrated medical, pediatric, dental, behavioral health, and veteran care to all patients regardless of insurance status or ability to pay. Because Kaniksu stores protected health information—including Social Security numbers and health records—on behalf of its patients, a breach involving that data carries significant risks of identity theft and medical fraud.
What Happened?
Kaniksu Community Health was listed in a Vermont Attorney General breach report summary dated September 5th, 2026. The incident was not a direct attack on Kaniksu’s own systems. Instead, Aesto LLC (doing business as Aesto Health), a Birmingham, Alabama-based healthcare data migration and archiving vendor, experienced a network security incident affecting a portion of its Amazon Web Services infrastructure. Between approximately December 2nd, 2025, and December 18th, 2025, an unauthorized actor may have accessed or acquired protected health information stored on Aesto’s network. The Vermont AG filing identifies Social Security numbers and health records as the categories of data involved in Kaniksu’s breach.
The notification timeline raises serious concerns. Aesto did not confirm data involvement until May 26th, 2026—roughly 190 days after the incident began—well beyond HIPAA’s 60-day notification requirement for business associates. Aesto then notified Kaniksu on June 26th, 2026, prompting Kaniksu to launch its own investigation with the help of a national cybersecurity firm. Kaniksu’s filing with the Vermont Attorney General followed on September 5th, 2026. The broader Aesto breach affected at least 35 healthcare provider clients and approximately 9,540,683 individuals in total, making it the second-largest confirmed healthcare data breach of 2026. No threat group has publicly claimed responsibility for the Aesto attack. Multiple law firms, including Edelson Lechtzin LLP, have announced investigations into the Aesto breach on behalf of affected patients across all Aesto clients, though no filed class action specifically naming Kaniksu has been identified. Kaniksu is offering twelve months of identity monitoring through Kroll to affected patients.
Key Facts at a Glance
- Company or Organization: Kaniksu Community Health
- Industry: Health Care (Federally Qualified Health Center)
- Location: Sandpoint, Idaho (with clinics in Bonners Ferry, Priest River, and Ponderay, Idaho)
- Incident type: Third-party vendor data breach (Aesto Health / Aesto LLC)
- Date of breach: December 18th, 2025
- Date breach discovered: May 26th, 2026
- Date of consumer notification: June 26th, 2026 (Aesto notified Kaniksu); September 5th, 2026 (Vermont AG filing by Kaniksu)
- Identity theft protection offered: Twelve months of identity monitoring through Kroll
- Litigation status: No class action specifically naming Kaniksu has been filed; multiple law firms have announced investigations into the broader Aesto Health breach
- Source: Vermont Attorney General breach report summary; Massachusetts AG – Kaniksu notification letter; BleepingComputer – Aesto Health breach; HIPAA Journal – Aesto Health breach; MedSecLedger – Kaniksu breach analysis
What Should You Do?
If you received a notice from Kaniksu Community Health, enroll in the twelve months of identity monitoring through Kroll before the deadline stated in your letter. Even if you have not yet received a notice, you can take protective steps now: place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion), and request your free credit reports at AnnualCreditReport.com to look for unfamiliar accounts or inquiries. Because health records were involved, review any Explanation of Benefits statements from your insurer and check your medical records for services you did not receive, which can be a sign of medical identity theft. If you spot suspicious activity, report it at IdentityTheft.gov for a personalized recovery plan.
Your Legal Rights
If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.