Aesto, LLC
bd_3a91ce22cef72ff3 · schema v1 · pii pii-v1
Full breach record for Aesto, LLC →Everside Health reported a data breach involving its third-party vendor, Aesto, LLC. Aesto, a healthcare data migration and archiving services provider, experienced a network security incident on its AWS infrastructure between December 2 and December 18, 2025. The breach potentially exposed protected health information (PHI) and personally identifiable information (PII) of a limited number of individuals. Aesto confirmed the unauthorized access on May 26, 2026, after forensic investigation. Everside Health was notified on June 26, 2026. No evidence of misuse was found, but affected individuals were offered credit monitoring services.
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-627495
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 31, 2026
- Raw hash
- cfb04c0456ad351e119c0838525a0bf740a5bce45501aba04dc2e7cbe58ff858
Reporting entity
- Name
- Everside Healthnorm: everside health
Victim entity
- Name
- Aesto, LLCnorm: aesto
Incident
- Discovered
- Dec 18, 2025
- Materiality determined
- —
- Notification sent
- Jun 26, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 32 weeks(225 days from discovery to filing)
- Compliance flags
- CA 60-day late · 190dCA AG copy >15d · 35d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Dec 18, 2025→ Notified: Jun 26, 2026190d 60 days (analyst band, pre-2026 discoveries) CA 60-day late California Consumers notified: Jun 26, 2026→ AG copy submitted: Jul 31, 202635d 15 calendar days CA AG copy >15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.