Aesto Health
bd_44b55c8508053bbd · schema v1 · pii pii-v2
Full breach record for Aesto Health →6 incidents on fileAesto LLC d/b/a Aesto Health, a healthcare data migration and archiving services provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor accessed and copied protected health information (PHI) and personally identifiable information (PII), including names, medical record numbers, Social Security numbers, and financial account numbers, between December 2 and December 18, 2025. Aesto detected the incident on December 18, 2025, and contained it. Forensic investigation confirmed the scope in May 2026. Valley Perinatal Services, LLC, a covered entity client, notified the New Hampshire Attorney General that 11 New Hampshire residents were affected. Notices were mailed to affected individuals in August 2026. Credit monitoring services were provided.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Aug 20, 2026
Filed
vs. sector median
+24 wks slower
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- New Hampshire State AGbd_bf704f7baef228c12026-08-19 · +1dCandidate
- California State AGbd_cb2bb8a2cd3f59b62026-08-25 · +5dVerified
- New Hampshire State AGbd_3b97726fa4a0fefa2026-08-11 · +9dCandidate
Filing propagation · 4 filings · 2 states
View merged incident ↗Pattern: first filing Aug 11 (NH), last Aug 25 (CA) — a 14-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.