Everside Health
bd_67f13a4222e41030 · schema v1 · pii pii-v1
Full breach record for Everside Health →3 incidents on fileNew Hampshire Attorney General notice regarding a security incident at Aesto, LLC, a third-party vendor for Everside Health. Aesto, which provides healthcare data migration services, experienced unauthorized access to AWS infrastructure between Dec 2-18, 2025. Approximately 442 NH residents' PII (names, DOB, SSN, MRNs) was potentially accessed. Notification letters were mailed on July 31, 2026, offering 12 months of credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Jun 26, 2026
Discovered
Jul 31, 2026
Filed
vs. sector median
6 wks faster
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- California State AGbd_3a91ce22cef72ff32026-07-31Candidate
- New Hampshire State AGbd_7afae1cfba7459a52026-07-31Verified
- Vermont State AGbd_ed89224a3d3fa39d2026-07-31Verified
- Massachusetts State AGbd_efc058e9ea799e382026-07-31Candidate
Show 1 more filing ↓Show fewer ↑up to 5d gap
- Oregon State AGbd_ffdc3411341bf72d2026-08-05 · +5dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Jul 31 (CA), last Aug 5 (OR) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.