DisclosureLens
HackingHealthcareHealthcareData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIdentity (basic)PHIHealth (basic)LowContained

Aesto Health

bd_3a91ce22cef72ff3 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 18, 2025

Filed

Jul 31, 2026

To disclose

32 weeks

Affected

Not disclosed

Linked

6 filings

Confidence

65%
Full breach record for Aesto Health6 incidents on file

Everside Health reported a data breach involving its third-party vendor, Aesto, LLC. Aesto, a healthcare data migration and archiving services provider, experienced a network security incident on its AWS infrastructure between December 2 and December 18, 2025. The breach potentially exposed protected health information (PHI) and personally identifiable information (PII) of a limited number of individuals. Aesto confirmed the unauthorized access on May 26, 2026, after forensic investigation. Everside Health was notified on June 26, 2026. No evidence of misuse was found, but affected individuals were offered credit monitoring services.

California clockDiscovered Dec 18, 2025Notified Jun 26, 2026190d CA 60-day late32 weeks discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 16 days
discovery → filing · 32 weeks / 225 days

Dec 2, 2025

Begins

Dec 18, 2025

Discovered

Jul 31, 2026

Filed

vs. sector median

+21 wks slower

This filing is one of 6 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (5) · sorted by filing gap

Show 1 more filingup to 5d gap

Filing propagation · 6 filings · 5 states

View merged incident ↗
New Hampshire State AGJul 31 · first
New Hampshire State AGJul 31 · first
Vermont State AGJul 31 · first
Massachusetts State AGJul 31 · first
California State AGJul 31 · first · this page

Pattern: first filing Jul 31 (NH), last Aug 5 (OR) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.