AESTO, LLC
ent_f12044780059db35ac23f1c0
Disclosures
21
State AG · HHS OCR · 5 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
9,540,683
nationwide · HHS OCR AL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- AESTO, LLC
- Normalized
- aesto— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (21)newest first
- Massachusetts State AGas reporting2026-09-01
Johnson Memorial Health System notified patients of a data breach involving their protected health information (PHI). The incident occurred at Aesto, LLC, a third-party vendor providing healthcare data migration and archiving services. An unauthorized actor accessed PHI stored on Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. The affected data includes full names and other health information. Johnson Memorial Health System is offering complimentary credit monitoring to affected individuals.
- Massachusetts State AGas victim2026-09-01
Aesto, LLC, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. Unauthorized access to protected health information (PHI) occurred between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and confirmed the scope of affected data on May 26, 2026. Affected individuals include residents of multiple states, including Massachusetts and Rhode Island. Aesto engaged external cybersecurity professionals, conducted a forensic investigation, and is offering complimentary identity monitoring services to affected individuals. No evidence of misuse was found.
- Massachusetts State AGas reporting2026-09-01
Catalyst Physician Group notified patients of a data breach involving their protected health information (PHI). The incident occurred at Aesto, LLC, a third-party vendor providing healthcare data migration and archiving services. An unauthorized actor accessed PHI stored in Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and confirmed the scope of the breach on May 26, 2026, after forensic investigation. Affected data includes full names and other PHI. Catalyst Physician Group is offering complimentary identity theft protection services to affected individuals.
- New Hampshire State AGas victim2026-08-28
Diana Health, Inc. notified the New Hampshire Attorney General of a data security incident involving its vendor, Aesto LLC d/b/a Aesto Health. Between December 2 and December 18, 2025, an unauthorized actor accessed and copied data from Aesto's AWS infrastructure. The incident impacted approximately 10 New Hampshire residents, exposing names, Social Security numbers, and other personal identifiers. Diana Health began mailing notices on August 28, 2026, and provided credit monitoring services.
- New Hampshire State AGas victim2026-08-27
Murfreesboro Medical Clinic reported a data breach involving its cloud provider, Aesto LLC, affecting 148 New Hampshire residents. Unauthorized access occurred between Dec 2-18, 2025, exposing PHI, SSNs, and financial data. MMC notified the NH AG on Aug 27, 2026, and mailed individual notices on Aug 26, 2026, offering 12 months of credit monitoring.
- California State AGas reporting2026-08-26
Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. Unauthorized access occurred between December 2 and December 18, 2025, and was detected on December 18, 2025. Protected health information, including names, dates of birth, medical info, driver's license numbers, financial account numbers, and Social Security numbers, may have been accessed or acquired. Murfreesboro Medical Clinic is one of the affected covered entities. Aesto contained the incident, engaged forensic experts, and is providing 12 months of credit monitoring to affected individuals.
- California State AGas victim2026-08-24
Aesto LLC, a healthcare data migration and archiving services provider, experienced a network security incident impacting its Amazon Web Services infrastructure. An unauthorized actor accessed and/or acquired personal information pertaining to care for some individuals between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. The affected data includes full names and other variable personal health information. Aesto notified its healthcare provider client, Allied Health MSO Holdco, LLC, on June 26, 2026. Aesto is offering complimentary credit monitoring and identity theft protection services to affected individuals.
- New Hampshire State AGas victim2026-08-21
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor copied data between December 2 and December 18, 2025. Aesto detected the incident on December 18, 2025, and confirmed the scope on May 26, 2026. The breach affected protected health information, including names, Social Security numbers, and financial account numbers, of approximately 16 New Hampshire residents of client Carolina Internal Medicine. Aesto contained the incident and engaged forensic experts. Notices were sent to affected individuals in August 2026.
- New Hampshire State AGas victim2026-08-21
Aesto LLC d/b/a Aesto Health, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor accessed and copied protected health information (PHI) and personally identifiable information (PII), including names, medical record numbers, Social Security numbers, and financial account numbers, between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Approximately 3 New Hampshire residents were affected. Aesto engaged forensic specialists, contained the incident, and notified affected individuals and regulators.
- Massachusetts State AGas reporting2026-08-01
University Surgical Associates, PLLC notified patients that their protected health information (PHI) may have been accessed by an unauthorized actor due to a network security incident at their third-party vendor, Aesto, LLC. The incident occurred between December 2 and December 18, 2025, and was discovered on December 18, 2025. Aesto confirmed the access after a forensic investigation. Affected data includes full names and other PHI. Aesto is offering credit monitoring services.
- Massachusetts State AGas reporting2026-08-01
Healthfirst Bluegrass, Inc. notified residents of a security incident at its third-party vendor, Aesto LLC, a healthcare data migration and archiving service provider. An unauthorized actor accessed Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. Affected data includes full names and potentially Social Security numbers (indicated by IRS IP PIN advice). The incident is contained. Healthfirst Bluegrass is offering 24 months of credit monitoring and identity theft protection. Rhode Island reported 6 affected residents; total Massachusetts count not explicitly stated in the provided text.
- Massachusetts State AGas reporting2026-08-01
Aesto, LLC, a healthcare data migration and archiving vendor for Surgeons Choice Medical Center (dba of Southfield Rehabilitation Company LLC), experienced a network security incident impacting its AWS infrastructure. An unauthorized actor copied protected health information (PHI) between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Forensic investigation confirmed data exfiltration. No evidence of misuse was found. Affected individuals in multiple states are offered 24 months of credit monitoring.
- Massachusetts State AGas reporting2026-08-01
Neighborhood HealthSource notified Massachusetts residents that a data security incident at Aesto, LLC, a third-party provider of healthcare data migration and archiving services, involved protected health information. The incident occurred via a third-party vendor compromise. No specific dates for discovery or occurrence were provided in the notice. Affected individuals were offered 24 months of Experian IdentityWorks and identity restoration services. The incident is considered contained.
- Illinois State AGas victim2026-08-01
AESTO, LLC filed a data-breach notice with the Illinois Attorney General in August 2026 (case 26-08-1371). The register records the breach as discovered on May 26, 2026. Personal information types reported: drivers license, financial account number, medical information, ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas reporting2026-08-01
Diana Health, Inc. notified patients of a data security incident at its vendor, Aesto, LLC, which provides healthcare data migration and archiving services. An unauthorized actor copied protected health information (PHI) and personal identifiers belonging to Diana Health patients stored on Aesto's AWS infrastructure between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025. Diana Health's own systems were not impacted. The company is offering complimentary credit monitoring services to affected individuals.
- Massachusetts State AGas reporting2026-08-01
Iroquois Memorial Hospital notified patients of a security incident at its business associate, Aesto LLC, which provides healthcare data migration and archiving services. An unauthorized actor accessed Aesto's AWS infrastructure between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Protected health information, including full names and other elements, may have been accessed or acquired. Aesto engaged external cybersecurity professionals and conducted a forensic investigation. Iroquois Memorial Hospital is offering complimentary credit monitoring to affected individuals.
- Illinois State AGas victim2026-08-01
AESTO, LLC filed a data-breach notice with the Illinois Attorney General in August 2026 (case 26-08-1382). The register records the breach as discovered on June 26, 2026. Personal information types reported: ssn. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas reporting2026-08-01
Aesto LLC, a healthcare data migration and archiving service provider, experienced a network security incident impacting its AWS infrastructure. Unauthorized access occurred between December 2 and December 18, 2025, and was discovered on December 18, 2025. Protected health information (PHI) for patients of Edwards County Medical Center, including names, dates of birth, ITINs, and medical record numbers, may have been accessed. Aesto notified affected entities on June 26, 2026, and is offering 24 months of credit monitoring. The incident is contained.
- Massachusetts State AGas reporting2026-08-01
Aesto, LLC, a healthcare data migration and archiving service provider for Carolina Internal Medicine, experienced a network security incident impacting its AWS infrastructure. An unauthorized actor copied protected health information (PHI) between December 2 and December 18, 2025. Aesto discovered the incident on December 18, 2025, and confirmed the scope of data exfiltration on May 26, 2026. Affected individuals include residents of multiple states. Aesto is offering 24 months of credit monitoring services.
- Massachusetts State AGas reporting2026-08-01
Aesto, LLC, a healthcare data migration and archiving service provider for Allied Health MSO Holdco, LLC, experienced a data security incident affecting personal information of Massachusetts residents. The incident involved a third-party vendor. Affected data types likely include PHI and PII (SSN, DOB, address). Aesto is offering 24 months of credit monitoring and identity theft protection. No specific dates for discovery or occurrence are provided in the notice letter.
- ALABAMAHHS OCRas victim2026-07-31
Aesto, LLC reported to HHS on 2026-07-31 a Hacking/IT Incident affecting 9540683 individuals. Breached information located on Network Server.