Aesto Health Breach Exposes Patient Data
Coverage from Federman & Sherwood, Claim Depot, and others

Aesto Health, a healthcare data migration and archiving provider, disclosed unauthorized access to limited Amazon Web Services infrastructure between December 2 and December 18, 2025.
The incident may have exposed protected health information and identity data held for clients including Everside Health and Lone Star Community Health Center, with state filings reporting affected residents in multiple states. The scale and sensitivity of the data create notification, identity-protection, and third-party security concerns for the provider organizations and affected patients.
The incident is now linked to additional provider organizations, with notifications extending into August 2026. This broadens the documented multi-provider impact, although the nationwide affected population and full provider list remain unresolved.
The incident is now shown to affect a far larger population and more client organizations than previously reported, led by Lone Star Community Health Center’s disclosure involving 250,130 Texas residents. The story also broadens to multi-state disclosures while clarifying that unauthorized acquisition has not been established for every record.
