DisclosureLens
HackingHealthcareHealthcareData ExfiltratedSupply Chain (3P Vendor)Business Associate (HIPAA)Customer Data InvolvedDelayed DiscoveryPHIHealth (basic)Identity (basic)LowContained

Community Health Center, Inc.

bd_ea23cc71e1a3a193 · schema v1 · pii pii-v1

Severity

Low

Discovered

Dec 18, 2025

Filed

Aug 10, 2026

To disclose

34 weeks

Affected

1state residents only

Linked

2 filings

Confidence

63%
Full breach record for Community Health Center, Inc.5 incidents on file

Midtown Community Health Center notified patients of a data breach involving their third-party vendor, Aesto, LLC. An unauthorized actor copied protected health information (PHI) and basic identity data from Aesto's AWS infrastructure between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Forensic investigation confirmed data exfiltration. Midtown is offering credit monitoring services to affected individuals.

Massachusetts clock MA AG >90d34 weeks discovery → filing

Incident timeline

undetected · 16 days
discovery → filing · 34 weeks / 235 days

Dec 2, 2025

Begins

Dec 18, 2025

Discovered

Aug 10, 2026

Filed

vs. sector median

+23 wks slower

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings · 2 states

View merged incident ↗
Vermont State AGAug 10 · first
Massachusetts State AGAug 10 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.