Diana Health, Inc.
bd_7cde2d19e328e52a · schema v1 · pii pii-v2
Full breach record for Diana Health, Inc. →2 incidents on fileDiana Health, Inc. notified patients of a data security incident at its vendor, Aesto, LLC, which provides healthcare data migration and archiving services. An unauthorized actor copied protected health information (PHI) and personal identifiers belonging to Diana Health patients stored on Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. Diana Health's own systems were not impacted. The company is offering complimentary credit monitoring services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Aug 1, 2026
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.