Aesto Health
bd_7afae1cfba7459a5 · schema v1 · pii pii-v1
Full breach record for Aesto Health →6 incidents on fileAesto, LLC, a third-party healthcare data migration vendor, experienced a network security incident on its AWS infrastructure between Dec 2-18, 2025. Unauthorized actors accessed patient records (names, SSNs, PHI) for 107,349 individuals, including 13 NH residents. Village Practice Management Company (VPM) notified the NH AG on July 31, 2026, after receiving confirmation from Aesto. Patients received notification letters and complimentary credit/identity monitoring via Epiq.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Jul 31, 2026
Filed
vs. sector median
+21 wks slower
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- California State AGbd_3a91ce22cef72ff32026-07-31Candidate
- New Hampshire State AGbd_67f13a4222e410302026-07-31Verified
- Vermont State AGbd_ed89224a3d3fa39d2026-07-31Verified
- Massachusetts State AGbd_efc058e9ea799e382026-07-31Candidate
Show 1 more filing ↓Show fewer ↑up to 5d gap
- Oregon State AGbd_ffdc3411341bf72d2026-08-05 · +5dVerified
Filing propagation · 6 filings · 5 states
View merged incident ↗Pattern: first filing Jul 31 (CA), last Aug 5 (OR) — a 5-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.