HealthFirst Bluegrass
bd_11f30faad6493805 · schema v1 · pii pii-v2
Full breach record for HealthFirst Bluegrass →4 incidents on fileHealthfirst Bluegrass, Inc. notified residents of a security incident at its third-party vendor, Aesto LLC, a healthcare data migration and archiving service provider. An unauthorized actor accessed Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. Affected data includes full names and potentially Social Security numbers (indicated by IRS IP PIN advice). The incident is contained. Healthfirst Bluegrass is offering 24 months of credit monitoring and identity theft protection. Rhode Island reported 6 affected residents; total Massachusetts count not explicitly stated in the provided text.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Aug 1, 2026
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.