Everside Health reported a data breach involving its third-party vendor, Aesto, LLC. Aesto, a healthcare data migration and archiving services provider, experienced a network security incident on its AWS infrastructure between December 2 and December 18, 2025. The breach potentially exposed protected health information (PHI) and personally identifiable information (PII) of a limited number of individuals. Aesto confirmed the unauthorized access on May 26, 2026, after forensic investigation. Everside Health was notified on June 26, 2026. No evidence of misuse was found, but affected individuals were offered credit monitoring services.