Everside Health
ent_3b3a81cf77769d1bce591dec
Disclosures
8
State AG · 7 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
1,389,758
nationwide · State AG TX
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Everside Health
- Normalized
- everside health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (8)newest first
- Texas State AGas victim2026-08-04
Everside Health based in Indianapolis, Indiana, a other entity reported a data breach to the Texas Attorney General. The breach was discovered on 2026-06-26 and reported on 2026-08-04. 22,210 Texas residents were affected. 1,389,758 individuals affected in total. Types of information involved: Name of individual;Address;Social Security Number Information;Medical Information;Date of Birth. Consumers were notified via U.S. Mail.
- California State AGas reporting2026-07-31
Everside Health reported a data breach involving its third-party vendor, Aesto, LLC. Aesto, a healthcare data migration and archiving services provider, experienced a network security incident on its AWS infrastructure between December 2 and December 18, 2025. The breach potentially exposed protected health information (PHI) and personally identifiable information (PII) of a limited number of individuals. Aesto confirmed the unauthorized access on May 26, 2026, after forensic investigation. Everside Health was notified on June 26, 2026. No evidence of misuse was found, but affected individuals were offered credit monitoring services.
- Washington State AGas victim2026-07-31
Everside Health, a healthcare provider, was notified by its business associate Aesto, LLC on June 26, 2026, of a security incident involving Aesto's AWS infrastructure. Between Dec 2-18, 2025, an unauthorized actor accessed PHI of ~21,308 Washington residents, including names, SSNs, DOBs, and medical record numbers. Aesto contained the incident, engaged forensic investigators, and began mailing notification letters on July 31, 2026, offering 12 months of credit monitoring.
- New Hampshire State AGas victim2026-07-31
New Hampshire Attorney General notice regarding a security incident at Aesto, LLC, a third-party vendor for Everside Health. Aesto, which provides healthcare data migration services, experienced unauthorized access to AWS infrastructure between Dec 2-18, 2025. Approximately 442 NH residents' PII (names, DOB, SSN, MRNs) was potentially accessed. Notification letters were mailed on July 31, 2026, offering 12 months of credit monitoring.
- Illinois State AGas victim2026-07-01
EVERSIDE HEALTH filed a data-breach notice with the Illinois Attorney General in July 2026 (case 26-07-1361). The register records the breach as discovered on June 26, 2026. Personal information types reported: medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- South Carolina State AGas victim2023-08-18
Everside Health notified South Carolina residents of a cybersecurity incident discovered on April 27, 2023. An unauthorized party accessed the network between April 22 and April 28, 2023, and copied documents containing personal information. Everside engaged a cybersecurity firm, notified law enforcement, and offered one year of complimentary credit monitoring via Experian IdentityWorks.
- Massachusetts State AGas victim2023-08-17
Everside Health reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-08-17. 9 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2023-08-17
Everside Health, a healthcare provider and HIPAA Business Associate, notified the NH Attorney General of a security incident affecting one New Hampshire resident. Unauthorized access occurred between April 22-28, 2023, resulting in the copying of documents containing PHI. Suspicious activity was detected on April 27, 2023. Everside engaged forensic investigators, notified law enforcement, and offered one year of credit monitoring to the affected individual.