Carolina Internal Medicine
bd_f7f835c38fe540f1 · schema v1 · pii pii-v2
Full breach record for Carolina Internal Medicine →Aesto, LLC, a healthcare data migration and archiving service provider for Carolina Internal Medicine, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor copied protected health information (PHI) between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and confirmed the scope of data exfiltration on May 26, 2026. Affected individuals include residents of multiple states. Aesto is offering 24 months of credit monitoring services.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Aug 1, 2026
Filed
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.