What Happened in the Everside Health Data Breach?
Everside Health recently sent notification letters to patients warning that their protected health information may have been exposed. The exposure did not stem from a direct attack on Everside Health itself. Instead, it traces back to Aesto, LLC, a Birmingham, Alabama company that handles data migration and archiving work for healthcare organizations across the country.
According to a notice filed with the California Attorney General, Aesto identified unusual activity within a portion of its Amazon Web Services environment. The intrusion took place between early and mid-December 2025. As a result, unauthorized access to Aesto’s network occurred in December 2025, though the company did not detect the activity until later that same month.
Once Aesto spotted the suspicious activity, it moved to contain the threat. The company then brought in outside cybersecurity specialists to figure out exactly what had happened and which files were touched. This forensic process included a manual review of the affected documents, which took several months to complete.
Aesto ultimately confirmed that protected health information belonging to patients of several covered entity clients, including Everside Health, may have been accessed or taken by an unauthorized party. Because Aesto serves multiple healthcare organizations at once, this single vendor incident had a ripple effect across more than one company’s patient population. Everside Health received word from Aesto and, in turn, began notifying its own patients whose records were involved.
Who was affected?
The people affected by this incident are patients who received care or services through Everside Health and whose information had been shared with or stored by Aesto for data migration or archiving purposes. Because Aesto works with numerous healthcare providers, the scope of the underlying incident extends beyond Everside Health alone, even though this notice concerns Everside Health’s own patient population specifically.
Neither Aesto nor Everside Health has publicly disclosed a specific number of affected individuals in the material reviewed here. What is clear is that the exposure varied by person. Some patients may have had only their names and dates of birth involved, while others may have had far more sensitive identifiers exposed, including Social Security numbers.
Because this breach involves a healthcare data vendor, the affected population likely includes a broad mix of patients, some of whom may have had little direct interaction with Aesto and may not have even known their records passed through that company. This is a common and often unsettling reality of vendor-driven breaches in healthcare.
What Information Was Potentially Exposed?
The categories of information involved in this incident differ from person to person, based on what Aesto held for each individual. However, the notice describes a fairly extensive list of potentially exposed data types tied to Everside Health patients.
- Full names
- Dates of birth
- Medical information
- Driver’s license numbers
- Financial account numbers
- Health insurance information
- Individual taxpayer identification numbers
- Other government-issued identification numbers
- Social Security numbers
Because Social Security numbers, driver’s license numbers, and financial account details may be involved, affected patients face a real and lasting risk of identity theft. This kind of information can be used to open new credit lines, file fraudulent tax returns, or take over existing financial accounts. These risks do not disappear once the initial notification period ends; stolen identifiers can be used or resold for years afterward.
In addition, the presence of medical information and health insurance details raises the possibility of medical identity theft. This happens when someone uses a victim’s insurance information to obtain treatment or submit fraudulent claims. Unlike ordinary financial fraud, medical identity theft can be harder to detect and may even affect a victim’s own medical records, creating confusion during future care.
What is the company doing?
After discovering the intrusion, Aesto contained the incident and engaged outside forensic experts to determine the scope of the compromise. This investigation involved a detailed, document-by-document review to identify precisely whose information had been involved. Aesto has stated that it has no current evidence that any exposed data has actually been misused for identity theft or fraud.
Even without confirmed misuse, Aesto is offering complimentary identity monitoring services to affected individuals as a precaution. Following completion of its investigation, Aesto notified its covered entity clients, including Everside Health, so those organizations could alert their own patients. Everside Health then sent individual notification letters describing the incident and encouraging recipients to remain alert for any signs that their information has been misused.
What Should Affected Individuals Do?
Enroll in Identity Monitoring Services
If you received a notification letter, take advantage of the complimentary identity monitoring being offered through Aesto’s notification process. This service can help flag suspicious activity tied to your personal information before it escalates into a bigger problem.
Because enrollment is typically time-limited, it helps to sign up as soon as possible after receiving your letter. Monitoring services generally cannot undo a breach, but they can give you an early warning if your data shows up somewhere it shouldn’t.
Place a Fraud Alert or Credit Freeze
Given that Social Security numbers, driver’s license numbers, and financial account numbers may have been exposed, consider placing a fraud alert or a full credit freeze with Equifax, Experian, and TransUnion. A freeze restricts access to your credit file, which makes it much harder for someone to open new accounts in your name.
A fraud alert is a lighter-touch option that requires lenders to verify your identity before extending credit. Either step is free to request, and you can lift a freeze temporarily whenever you need to apply for credit yourself.
Watch for Medical and Insurance Fraud
Because health insurance information and medical details may have been exposed, review your explanation-of-benefits statements and medical bills closely. Look for any services, providers, or charges that you do not recognize.
If you spot something unfamiliar, contact your insurance provider immediately to report it. Catching medical identity theft early can prevent inaccurate information from becoming part of your permanent medical record.
Monitor Financial Accounts and Credit Reports
In addition to freezing your credit, regularly review your bank and credit card statements for unauthorized transactions. Small, unfamiliar charges are sometimes a test run before larger fraudulent activity follows.
You are also entitled to a free credit report from each of the three major bureaus every year. Reviewing these reports periodically can help you catch new accounts or inquiries you did not authorize.
Stay Alert for Phishing Attempts
Scammers often use news of a data breach to send fake emails, texts, or phone calls pretending to be from the breached company. Be cautious of any unexpected message referencing this incident that asks you to click a link or share personal information.
Instead of responding directly, verify any communication by contacting Everside Health or Aesto through official channels. If something feels off, it probably is, and it is always safer to double-check before sharing sensitive details.
More Information
Official data breach notification from California Attorney General
