University Surgical Associates
bd_03da71f3e87ff0c2 · schema v1 · pii pii-v2
Full breach record for University Surgical Associates →2 incidents on fileUniversity Surgical Associates, PLLC notified patients that their protected health information (PHI) may have been accessed by an unauthorized actor due to a network security incident at their third-party vendor, Aesto, LLC. The incident occurred between December 2 and December 18, 2025, and was discovered on December 18, 2025. Aesto confirmed the access after a forensic investigation. Affected data includes full names and other PHI. Aesto is offering credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Aug 1, 2026
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.