Aesto Health
bd_b48dbb172911c31e · schema v1 · pii pii-v2
Full breach record for Aesto Health →6 incidents on fileAesto, LLC, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor accessed and/or acquired protected health information (PHI) between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and confirmed the scope of data exposure on May 26, 2026. Affected data includes full names and health-related information. Aesto engaged external cybersecurity professionals, notified healthcare providers, and offered credit monitoring services to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Aug 20, 2026
Filed
vs. sector median
+24 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- New Hampshire State AGbd_c547969d194bb5d12026-08-07 · +13dVerified
- Washington State AGbd_6ba6b179ea4373bf2026-08-04 · +16dCandidate
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Aug 4 (WA), last Aug 20 (CA) — a 16-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.