Aesto Health
ent_4f61d45dbb20101899ff661f
Disclosures
24
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
8
incidents joining 2+ filings here
Max affected reported
107,349
nationwide · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Aesto Health
- Normalized
- aesto health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- aestohealth.com
Disclosure history (24)newest first
- California State AGas victim2026-08-25
Together Women's Health LLC (Aesto) reported a data breach affecting individuals in multiple states, including California. The incident occurred between December 2 and December 18, 2025. Affected data includes Social Security numbers, basic identity information, and protected health information. The organization established a toll-free response line for affected individuals. No specific attack vector or threat actor was identified in the filing.
- California State AGas reporting2026-08-20
Nebraska Orthopaedic Center, P.C. notified California residents that a third-party vendor, Aesto LLC, experienced a security incident. Between December 2 and December 18, 2025, an unauthorized actor copied protected health information, including names, medical record numbers, dates of birth, and Social Security numbers. Aesto detected the incident on December 18, 2025. The organization engaged external cybersecurity professionals and is offering 12 months of credit monitoring to affected individuals.
- New Hampshire State AGas victim2026-08-20
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving services provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor accessed and copied protected health information (PHI) and personally identifiable information (PII), including names, medical record numbers, Social Security numbers, and financial account numbers, between December 2 and December 18, 2025. Aesto detected the incident on December 18, 2025, and contained it. Forensic investigation confirmed the scope in May 2026. Valley Perinatal Services, LLC, a covered entity client, notified the New Hampshire Attorney General that 11 New Hampshire residents were affected. Notices were mailed to affected individuals in August 2026. Credit monitoring services were provided.
- California State AGas victim2026-08-20
Aesto, LLC, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor accessed and/or acquired protected health information (PHI) between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and confirmed the scope of data exposure on May 26, 2026. Affected data includes full names and health-related information. Aesto engaged external cybersecurity professionals, notified healthcare providers, and offered credit monitoring services to affected individuals.
- New Hampshire State AGas victim2026-08-19
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor copied data between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Affected data for Nebraska Orthopaedic Center patients included names, Social Security numbers, medical record numbers, dates of birth, and financial account numbers. Approximately 47 New Hampshire residents were affected. Aesto engaged forensic specialists, contained the incident, and is offering credit monitoring services.
- Nebraska State AGas victim2026-08-12
Aesto, LLC d/b/a Aesto Health experienced a network security incident impacting its AWS infrastructure between December 2 and December 18, 2025. The unauthorized access potentially exposed protected health information (PHI), including names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance info, ITINs, government IDs, and Social Security numbers. Aesto notified affected Covered Entity clients on June 26, 2026. No evidence of identity theft or fraud was found. The incident was contained to a limited portion of Aesto's AWS infrastructure.
- Massachusetts State AGas reporting2026-08-12
Tapestry 360 Health notified the Massachusetts Attorney General of a data breach affecting personal information of minors. The notice mentions Rhode Island residents specifically (3 impacted). The company established a toll-free response line and offered credit monitoring via TransUnion, Experian, and Equifax. The specific nature of the breach, dates, and total affected count are not detailed in the provided excerpt.
- New Hampshire State AGas victim2026-08-12
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor accessed and copied data between December 2 and December 18, 2025. The incident was detected on December 18, 2025. Affected data included PHI, names, SSNs, driver's license numbers, and financial account numbers for patients of Covered Entity clients, including Tapestry 360 Health. Approximately 4 New Hampshire residents were affected. Aesto engaged forensic specialists, contained the incident, and notified clients and regulators.
- New Hampshire State AGas victim2026-08-11
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor accessed and copied data between December 2 and December 18, 2025. Aesto detected the incident on December 18, 2025, and confirmed the scope on May 26, 2026. Affected data included PHI, names, SSNs, and financial account numbers for patients of Covered Entity clients, including Shenandoah Valley Medical System. Approximately 23 New Hampshire residents were notified via mail starting August 11, 2026. Aesto engaged forensic specialists, contained the incident, and offered credit monitoring.
- New Hampshire State AGas victim2026-08-10
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor copied protected health information, including names, SSNs, and medical data, between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. One New Hampshire resident was affected. Aesto engaged forensic experts, contained the incident, and notified clients. Credit monitoring services were offered to affected individuals.
- Massachusetts State AGas reporting2026-08-10
Midtown Community Health Center notified patients of a data breach involving their third-party vendor, Aesto, LLC. An unauthorized actor copied protected health information (PHI) and basic identity data from Aesto's AWS infrastructure between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Forensic investigation confirmed data exfiltration. Midtown is offering credit monitoring services to affected individuals.
- Massachusetts State AGas reporting2026-08-07
Gila Health Resources, LLC notified Massachusetts residents that a third-party vendor, Aesto, LLC, experienced a network security incident affecting its AWS infrastructure. Unauthorized access to protected health information occurred between December 2 and December 18, 2025. Aesto detected unusual activity on December 18, 2025. The incident involved PHI including names, addresses, and potentially SSNs. Aesto engaged forensic investigators and contained the incident. Gila Health Resources is offering 12 months of credit monitoring to affected individuals.
- Nebraska State AGas reporting2026-08-07
Aesto, LLC, a healthcare data migration provider for Gila Health Resources, LLC, reported a cybersecurity incident involving its AWS infrastructure. Unauthorized access occurred between December 2 and December 18, 2025. Aesto confirmed that a limited amount of protected health information (PHI) was accessed. No evidence of misuse was found. Gila Health Resources offered 12 months of credit monitoring to affected individuals. The notification was sent on August 7, 2026.
- New Hampshire State AGas victim2026-08-07
Aesto LLC experienced a network security incident impacting its AWS infrastructure. Unauthorized access to sensitive information pertaining to HIPAA Covered Entity Clients occurred between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and notified affected Covered Entities on June 26, 2026. The incident is contained. No evidence of misuse was found.
- Oregon State AGas victim2026-08-05
Aesto, LLC reported a data breach to the Oregon Attorney General. The breach was reported on 2026-08-05. The breach occurred during 12/2/2025 - 12/18/2025. The breach was discovered on 12/18/2025. 1 individuals were affected. Notice was sent on 6/26/20267/31/2026.
- Washington State AGas victim2026-08-04
Aesto, LLC reported unauthorized access to its AWS infrastructure between Dec 2 and Dec 18, 2025. The incident impacted sensitive information pertaining to HIPAA Covered Entity Clients. Aesto notified affected entities on June 26, 2026. 37,253 Washington residents were affected. No evidence of misuse was found.
- Massachusetts State AGas reporting2026-08-01
Aesto, LLC, a healthcare data migration and archiving vendor for Greenwood County Hospital, experienced a network security incident impacting its AWS infrastructure. Unauthorized access occurred between December 2 and December 18, 2025, and was discovered on December 18, 2025. Protected health information, including full names and potentially other health data, for patients of Greenwood County Hospital may have been accessed or acquired. Aesto engaged external cybersecurity professionals and forensic investigators. The incident is contained. Credit monitoring services are being offered to affected individuals.
- Massachusetts State AGas reporting2026-08-01
Nebraska Orthopaedic Center, P.C. notified patients of a data breach involving their protected health information. The incident occurred at Aesto, LLC, a third-party healthcare data migration and archiving service provider. Between December 2 and December 18, 2025, an unauthorized actor copied PHI including names, medical record numbers, dates of birth, and Social Security numbers from Aesto's AWS infrastructure. Aesto discovered the incident on December 18, 2025. The breach affected residents of Massachusetts and Rhode Island. Nebraska Orthopaedic Center is offering 24 months of credit monitoring services.
- California State AGas victim2026-07-31
Everside Health reported a data breach involving its third-party vendor, Aesto, LLC. Aesto, a healthcare data migration and archiving services provider, experienced a network security incident on its AWS infrastructure between December 2 and December 18, 2025. The breach potentially exposed protected health information (PHI) and personally identifiable information (PII) of a limited number of individuals. Aesto confirmed the unauthorized access on May 26, 2026, after forensic investigation. Everside Health was notified on June 26, 2026. No evidence of misuse was found, but affected individuals were offered credit monitoring services.
- New Hampshire State AGas victim2026-07-31
Aesto, LLC, a third-party healthcare data migration vendor, experienced a network security incident on its AWS infrastructure between Dec 2-18, 2025. Unauthorized actors accessed patient records (names, SSNs, PHI) for 107,349 individuals, including 13 NH residents. Village Practice Management Company (VPM) notified the NH AG on July 31, 2026, after receiving confirmation from Aesto. Patients received notification letters and complimentary credit/identity monitoring via Epiq.
- Vermont State AGas victim2026-07-31
Aesto Health reported a data breach to the Vermont Attorney General. The breach was reported to the AGO on 2026-07-31. The reporting organization type is Health Care. 91 Vermont residents were affected. Categories of data breached: Social Security Numbers, Health Records.
- Massachusetts State AGas victim2026-07-31
Aesto, LLC, a healthcare data migration service provider, experienced a network security incident impacting its AWS infrastructure between December 2 and 18, 2025. Unauthorized actors accessed a limited amount of protected health information (PHI) and personal data (names, SSNs, DOBs) of patients. Aesto confirmed the breach on May 26, 2026, and notified affected healthcare providers on June 26, 2026. No evidence of misuse was found. Affected individuals were offered credit monitoring via Epiq.
- Nebraska State AGas reporting2026-07-02
Aesto LLC, on behalf of Shenandoah Valley Medical System, Inc. (d/b/a Shenandoah Community Health), issued a data breach notification in Nebraska. The incident involved the unauthorized access to minor's information, including government identifiers (SSN, DOB) and basic identity data. The organization provided free credit monitoring and fraud assistance via Cyberscout (TransUnion) and established a toll-free response line. The specific attack vector and discovery date are not detailed in the notification letter.
- ALABAMAHHS OCRas victim2022-05-20
Aesto, LLC d/b/a Aesto Health (AL) reported to HHS on 2022-05-20 a Hacking/IT Incident (ransomware attack) affecting 17,400 individuals. Breached PHI was located on a Network Server and included names, dates of birth, and clinical information. The CE notified HHS, affected individuals, and the media, provided substitute notice, and implemented additional administrative, technical, and security safeguards in response.