(Todos los artículos de este sitio pueden ser traducidos por su navegador web.)
A letter arriving in mailboxes across the 98848 this week contains words guaranteed to get someone’s attention: Notice of Data Breach. For current and former Quincy Valley Medical Center patients, the natural questions are whether the hospital was hacked, what information was exposed and why they are only hearing about an incident that happened last December. The short answer is that QVMC’s computer system was not breached. The incident occurred at Aesto, a third-party company that stores historical QVMC records from a previous electronic medical record system. But that does not mean the letter should be ignored. Some patient information stored with Aesto may have been accessed by an unauthorized actor, and QVMC officials say understanding the difference between those two facts is important.
TL;DR
Quincy Valley Medical Center itself was not breached. The security incident occurred at Aesto, a third-party healthcare data migration and archiving company used by QVMC.
The QVMC information involved is largely archived historical information from the hospital’s previous electronic medical record system, rather than its current EMR.
Aesto says the security incident occurred in December 2025 and affected part of its Amazon Web Services infrastructure.
Aesto determined on May 26, 2026, that some protected health information belonging to QVMC patients may have been accessed or acquired by an unauthorized actor.
QVMC says it was notified July 7, not when the original incident occurred in December.
QVMC then had to determine who was affected and how to notify nearly 39,000 people connected to its historical records.
Potentially affected information includes names and data such as Social Security numbers and medical record numbers. Aesto says it has found no evidence that the information has been misused.
QVMC authorized the notification letters to be mailed August 5.
Anyone with questions can contact QVMC’s compliance team at Compliance@quincyhospital.org. The Aesto notification letter also provides a dedicated response line at 833-918-8060 and instructs callers to use engagement number B167683.
The Breach Was at Aesto, Not QVMC
QVMC CEO Glenda Bishop and Director of Information Systems Tom Richardson sat down with Life in the 98848 Thursday to explain what happened after questions began circulating about the letters.
The first distinction Richardson made is the most important one: this was not a breach of QVMC’s computer network.
Aesto is a healthcare technology company that provides data migration and archiving services. Hospitals periodically replace the electronic medical record software they use, but changing systems does not mean old patient records can simply be thrown away. Those records still have to be retained, and companies such as Aesto specialize in preserving that historical information.
Richardson said the scope of the Aesto incident extended far beyond Quincy. While approximately 39,000 records connected to QVMC were identified as potentially affected, he said the overall breach involved roughly 9 million people nationwide. QVMC, he said, represents only a small portion of the larger incident.
QVMC has used Aesto since 2017. Richardson said this is the first security incident the hospital has encountered during that nine-year relationship. The vast majority of the Quincy information involved, he said, is archived information from QVMC’s previous electronic medical record system.
That helps explain something some families are already encountering. Letters have arrived for former patients who have died, people who have moved away and, in some cases, people associated with addresses that no longer appear to make sense. These are not necessarily records from a recent visit to the new Quincy Valley Medical Center. In many cases, they reach back into QVMC’s history.
Aesto’s notification says the company experienced a network security incident on or about Dec. 18, 2025, affecting a limited portion of its Amazon Web Services infrastructure. After an investigation involving outside cybersecurity professionals and a manual review of documents, Aesto determined on May 26 that some protected health information may have been accessed or acquired by an unauthorized actor between approximately Dec. 2 and Dec. 18.
The potentially affected information includes patients’ full names and data points such as Social Security numbers and medical record numbers. Aesto says it has no evidence that the information has been misused.
That is the breach described in the letter. What happened next explains why Quincy patients are hearing about it now.
Why Did It Take Until August?
The December date understandably jumps off the page. Read by itself, it can create the impression that QVMC knew about a patient-data problem for months before notifying the community.
According to Bishop and Richardson, that is not what happened.
QVMC says it received its first notification from Aesto on July 7. Even then, Richardson said, the initial information was ambiguous enough that hospital officials did not immediately believe Quincy patient records were among those affected. After reading further, Richardson found language allowing QVMC to request additional information if it believed its data might be involved.
He submitted the request.
Richardson recalled telling Bishop that evening he was “99% sure” the list they received back would contain nothing involving QVMC.
Within roughly 24 hours, they learned otherwise.
The list contained approximately 39,000 records connected to QVMC. Suddenly, the question was no longer whether Quincy was involved.
Bishop said they had to consult with their legal team, the hospital has never had a reportable event. There were no established guidelines, processes or parameters for what they needed to do legal or practically. Bishop noted that the insurance company was surprised it was a new experience for QVMC because data breaches of this nature are not uncommon in the medical profession.
Hospital officials had to determine how to notify tens of thousands of people using information pulled largely from an old medical record system. Bishop said she initially began calculating postage, envelopes, paper and how many employees it would take to prepare 39,000 letters. Richardson’s immediate response was that the hospital would need to buy a folding machine.
The exchange is almost humorous now, but it illustrates the practical problem that landed on a small rural hospital’s desk. QVMC had previously handled a required patient mailing involving hundreds of letters many years ago by having employees print labels and stuff envelopes. This was tens of thousands.
And the list itself was not clean.
Some entries were duplicates. Some contained incomplete addresses. Some former patients had died. Some information had been entered incorrectly years earlier, while other records contained names of departments rather than actual people.
Hospital officials also found old records associated with patients treated around Gorge Amphitheatre events. Bishop said there were years when hospital staff regularly dealt with incomplete addresses or information that did not match a patient’s identification or insurance after concert weekends. Richardson said some patients simply wanted to be treated without providing much personal information. Those old registration problems are still reflected in the archived data today. Bishop used an old computer expression to describe it: “garbage in, garbage out.” Whatever went into those records years ago was still there when the archive produced the list.
QVMC ultimately contracted with a company capable of processing the data, removing duplicates and filtering some invalid addresses and known deceased individuals before handling the massive task of mailing approximately 39,000 letters. Even that could not catch everything. Bishop and Richardson said the hospital has already heard from people receiving letters addressed to deceased relatives or former residents.
That is why a letter showing up at an unexpected address does not necessarily mean someone recently used that address at QVMC. It may simply be the address attached to a historical record when it was created.
The hospital authorized the letters to be mailed Aug. 5.
“We haven’t known for eight and a half months,” Bishop said. “We did respond within the 30-day timeline.”
What Happens After a Vendor Reports a Breach
The situation also offers a look at something patients rarely have reason to think about: what happens behind the scenes when a hospital learns that another company holding its information has experienced a security problem.
For QVMC, this was the first reportable event of its kind, Richardson said. The hospital had to determine what information was involved, consult with insurance representatives, understand its notification obligations and figure out how to contact approximately 39,000 potentially affected people.
Aesto provided the notification-letter templates, but even those were complicated by the age of the data. One version was intended for parents of minors, for example. If the underlying record is decades old, however, someone who was a child when the record was created may be well into adulthood today. Another template addressed deceased patients, but QVMC had no reliable way to identify every person in the historical database who had since died.
Rather than trying to guess, the hospital moved forward with the broader notification.
Bishop said QVMC also carefully reviews the companies that have access to patient information. The hospital reviews its vendor contracts annually, including services that may have only an indirect connection to patients. A company that destroys old documents, for example, may never provide medical care, but it can still come into contact with protected patient information.
Aesto falls under that same scrutiny.
“We carefully vet our vendors, particularly related to information systems, how our records are stored, where they’re stored,” Bishop said. QVMC also has a compliance committee that meets weekly. Richardson serves as the hospital’s security officer, responsible for electronic information security, which is why his name appears on the notification sent to patients.
Those systems existed before this incident. What this event has done is test them in a way the hospital had not previously experienced.
What This Means to You
For current QVMC patients, the most important fact is that hospital officials say the breach did not occur inside QVMC’s current computer system. The affected QVMC information was largely historical data being maintained by Aesto from the hospital’s previous electronic medical record system.
For anyone who received a letter, however, the notification should still be taken seriously.
Aesto says potentially affected information includes a person’s full name and data points such as a Social Security number and medical record number. The company says it has no evidence that the information has been misused, but recommends that recipients remain vigilant by reviewing financial statements and credit reports. The letter also explains how to place fraud alerts or security freezes on credit files and includes precautions related to medical information.
Receiving the letter does not mean QVMC or Aesto knows that someone stole your identity or used your medical information. It means your information was among data that may have been accessed or acquired, and you are being notified so you can take reasonable precautions.
Anyone who still has questions after reading the Aesto letter can contact QVMC’s compliance team at Compliance@quincyhospital.org. Richardson said he is willing to answer what the hospital can answer.
“Please, if you have questions, reach out,” Richardson said. “We can have a conversation.”
That accessibility matters in the 98848. QVMC is not a distant corporate hospital system whose executives are names on a website. Bishop, Richardson and the hospital staff live and work in the same community as the people receiving these letters, and Bishop said the responsibility to protect patient information is personal for them as well.
“This is our health information, too,” Bishop said. “We treat this information as though it’s ours because it is.”
The Letter Is Serious. So Is Getting the Story Right.
There are two facts that have to remain together for the community to understand this incident accurately.
The first is that protected information belonging to current and former QVMC patients may have been accessed through a security incident involving Aesto. Some of that information can include Social Security numbers and medical record numbers. People who receive the letter have every reason to read it carefully and take the recommended precautions.
The second is that QVMC itself was not hacked. Hospital officials say they did not know about the incident when it happened in December and did not receive their first notification from Aesto until July 7. They then had to identify what the notice meant for Quincy, work through approximately 39,000 historical records and arrange notification. The letters were authorized for mailing Aug. 5.
Neither fact cancels out the other.
People across the 98848 have trusted Quincy Valley Medical Center with deeply personal information for decades. Some are now learning that pieces of that history were caught in a security incident at the outside company hired to preserve those records. They deserve to know that happened, what information may have been involved and what precautions they can take.
They also deserve the context behind the words printed across the top of the letter arriving in their mailbox.
For the 98848, that context is important: the notice of a data breach is real, but the breach was not at Quincy Valley Medical Center.






