Aesto Health
bd_3a91ce22cef72ff3 · schema v1 · pii pii-v1
Full breach record for Aesto Health →6 incidents on fileEverside Health reported a data breach involving its third-party vendor, Aesto, LLC. Aesto, a healthcare data migration and archiving services provider, experienced a network security incident on its AWS infrastructure between December 2 and December 18, 2025. The breach potentially exposed protected health information (PHI) and personally identifiable information (PII) of a limited number of individuals. Aesto confirmed the unauthorized access on May 26, 2026, after forensic investigation. Everside Health was notified on June 26, 2026. No evidence of misuse was found, but affected individuals were offered credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Jul 31, 2026
Filed
vs. sector median
+21 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- New Hampshire State AGbd_67f13a4222e410302026-07-31Verified
- New Hampshire State AGbd_7afae1cfba7459a52026-07-31Verified
- Vermont State AGbd_ed89224a3d3fa39d2026-07-31Verified
- Massachusetts State AGbd_efc058e9ea799e382026-07-31Candidate
Show 1 more filing ↓Show fewer ↑up to 5d gap
- Oregon State AGbd_ffdc3411341bf72d2026-08-05 · +5dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Jul 31 (NH), last Aug 5 (OR) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.