Everside Health has notified patients that their personal and protected health information may have been exposed as a result of a data security incident at Aesto, LLC, a Birmingham, Alabama-based company that provides healthcare data migration and archiving services to healthcare providers and other covered entities, including Everside Health. Companies that entrust sensitive patient records to a third-party vendor remain responsible for ensuring that vendor adequately protects that information, and this incident highlights the risk patients face when their data passes through outside service providers they may never have directly interacted with.
Everside Health’s Data Breach Investigation
According to a notice filed with the California Attorney General, Aesto experienced a network security incident that impacted a limited portion of its Amazon Web Services infrastructure. Upon detecting the unauthorized activity, Aesto contained the incident and began a forensic investigation with the assistance of outside cybersecurity professionals to determine what information, if any, had been accessed or acquired.
After an extensive investigation and manual document review, Aesto confirmed that certain protected health information belonging to patients of its covered entity clients, including Everside Health, may have been accessed or acquired by an unauthorized actor. Aesto began notifying its covered entity clients whose patient information was included in the affected files, and Everside Health in turn began notifying its own patients whose information was involved.
Vendor breaches like this one are becoming an increasingly common source of healthcare data exposure. Rather than a hacker directly targeting a hospital, clinic, or employer health center, attackers often go after the third-party companies that provide behind-the-scenes services such as data migration, billing, or records archiving for many healthcare organizations at once. A single vendor compromise can therefore expose patient information belonging to numerous unrelated healthcare providers and their patients simultaneously, which is part of why this incident affected multiple covered entities beyond Everside Health alone.
Aesto has stated it has no evidence to date that any of the information involved has been misused for identity theft or financial fraud. Even so, the company is offering complimentary identity monitoring services to affected individuals as a precaution, and it recommends that anyone who receives a notification letter remain vigilant for signs of misuse.
Because the exposed data can include Social Security numbers, driver’s license numbers, government identification numbers, and financial account information, affected individuals face a meaningfully elevated risk of identity theft, tax fraud, and account takeover attempts for months or years after the initial incident, not just in the immediate aftermath of notification. Medical information and health insurance details, when combined with these other identifiers, can also be used to commit medical identity theft or insurance fraud, which can be more difficult for a victim to detect and unwind than ordinary financial fraud.
When Did This Breach Occur?
Aesto states that the unauthorized access to its systems occurred between on or about December 2, 2025, and December 18, 2025, with the security incident itself first detected on December 18, 2025. Aesto confirmed on May 26, 2026, following its forensic investigation, that protected health information belonging to patients of various covered entity clients may have been involved. Aesto began notifying its covered entity clients, including Everside Health, on or around June 26, 2026, and Everside Health subsequently notified its own affected patients.
What Information Was Breached?
According to Aesto’s public notice, the information potentially accessed or acquired varied by individual and could include full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, individual taxpayer identification numbers, other government-issued identification numbers, and Social Security numbers, with Social Security numbers potentially involved for a more limited number of individuals. Everside Health’s own notice to affected patients did not specify which of these categories applied to each individual recipient, so patients who received a letter should review it directly to determine exactly what information of theirs may have been involved.
What You Can Do
If you received a notification letter regarding this incident, consider taking the following steps:
- Enroll in the complimentary identity monitoring services being offered through Aesto’s notification process.
- Place a fraud alert or security freeze with Equifax, Experian, and TransUnion.
- Review your medical bills, insurance statements, and explanation-of-benefits notices for any services or charges you do not recognize.
- Monitor your financial accounts and credit reports closely for unauthorized activity.
- Be cautious of unexpected calls, emails, or texts referencing this breach and asking for personal information.
File a Data Breach Lawsuit Against Everside Health
If you received a data breach notification connected to Everside Health or its vendor Aesto, you may be entitled to compensation. Healthcare providers and the vendors they rely on to store and manage patient records have a responsibility to protect that information from unauthorized access.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.