The data breach affecting Everside Health demonstrates how an organization’s cybersecurity exposure extends beyond the systems it operates directly. The incident originated at Aesto LLC, a third-party provider offering healthcare data migration and archiving services, which was storing protected health information on behalf of Everside Health.
Aesto experienced a network security incident affecting part of its Amazon Web Services infrastructure in December 2025. Following an investigation and review of the files stored within the affected environment, the company determined that an unauthorized actor may have accessed or acquired protected health information between December 2 and December 18, 2025.
The information potentially exposed included individuals’ full names, Social Security numbers and health records. The total number of affected individuals has not been publicly disclosed, leaving uncertainty regarding the overall scale of the incident.
This combination of identity and medical information creates serious and potentially long-lasting risks for affected individuals. Social Security numbers can be misused for identity theft, fraudulent credit applications, tax fraud and account-recovery attacks, while health records can support targeted phishing, insurance fraud, extortion and highly personalized social-engineering campaigns.
Third-party services remain part of the healthcare attack surface
Healthcare organizations frequently depend on specialist vendors to migrate, archive, process, store and analyze patient information. These services may improve operational efficiency, reduce infrastructure requirements and support access to historical records, but they also distribute sensitive information across a wider technology ecosystem.
The organization providing medical services may maintain strong security controls within its own network while still being exposed through a supplier holding copies of the same patient information. An attacker does not need to compromise the healthcare provider directly when a vendor stores valuable records in an environment that may be easier to reach.
Third-party risk should therefore not be treated as a procurement exercise completed before a contract is signed. It requires continuous assessment throughout the vendor relationship, including reviews of access controls, cloud configurations, logging, incident detection, data retention and subcontractor use.
Outsourcing the storage or processing of health information does not outsource responsibility for understanding where that information is located and how it is protected. The infrastructure may belong to the vendor, but the consequences of exposure continue to affect the healthcare organization and its patients.
Cloud infrastructure does not automatically guarantee secure data
The affected information was reportedly stored within a portion of Aesto’s Amazon Web Services environment. This does not mean that the underlying AWS platform was necessarily compromised or responsible for the incident.
Cloud providers generally protect the underlying infrastructure, while customers remain responsible for identities, permissions, applications, storage configurations, access keys and the information placed within the environment. A cloud platform can offer strong security capabilities, but those controls must be configured, monitored and maintained correctly by the organization using them.
Common cloud risks include excessive permissions, exposed credentials, insecure application interfaces, compromised administrator accounts, long-lived access keys and insufficient monitoring of bulk file access. Attackers may also exploit trusted integrations or use valid credentials in ways that do not immediately resemble conventional malware activity.
Healthcare organizations and their vendors should therefore maintain centralized visibility into cloud authentication, administrative changes, file access, data exports and unusual network activity. A legitimate account downloading an abnormal volume of archived patient files should receive scrutiny even when the platform itself continues operating normally.
Archived information remains valuable to attackers
Data archiving is often viewed primarily as a storage and compliance function. However, archived healthcare information can remain highly valuable because it may contain historical identity, treatment and insurance records collected over many years.
Older information does not automatically become harmless. A Social Security number remains useful for identity fraud, while medical history can continue revealing deeply personal information long after the original treatment occurred.
Archives may also contain information associated with former patients, employees or customers who no longer actively interact with the organization. This can make notification and remediation more difficult because contact details may be outdated and individuals may not expect the organization or vendor to still hold their information.
Organizations should therefore review how long archived records genuinely need to be retained. Legal, regulatory and clinical requirements may justify long retention periods, but data should not be preserved indefinitely merely because storage has become inexpensive.
Every retained file increases the amount of information that can be exposed during a future compromise. Data that no longer serves a legitimate business, medical or regulatory purpose should be securely deleted according to documented retention policies.
Health records and Social Security numbers create combined risk
The exposure of a name and Social Security number already creates a significant identity-theft risk. When health information is included, attackers gain additional context that can make fraudulent communications more believable and potentially more harmful.
A criminal may impersonate a healthcare provider, insurer, employer-sponsored health service or claims administrator while referring to genuine details obtained through the breach. Messages may claim that the individual must confirm coverage, pay an outstanding medical bill, schedule an appointment or verify information following the incident.
Because the communication contains real personal or medical details, the recipient may be more likely to trust it. Attackers can exploit the sensitivity of healthcare information to create urgency and discourage victims from checking with another person before responding.
Affected individuals should therefore be cautious about unexpected calls, emails and messages referring to Everside Health, Aesto, medical benefits or identity-protection services. Legitimate organizations should not request passwords, payment-card details or complete Social Security numbers through unsolicited communications.
Medical identity theft can be difficult to detect
Healthcare data can be misused to obtain treatment, prescriptions or insurance benefits under another person’s identity. This form of fraud may create financial consequences and can also contaminate the victim’s medical history.
Incorrect information added to a patient record could potentially affect future care if healthcare professionals rely on treatment, allergy or prescription details associated with another person. The consequences can therefore extend beyond privacy and financial harm.
Affected individuals should review insurance statements and explanations of benefits for unfamiliar providers, treatments or claims. Unexpected bills, notifications from unknown healthcare facilities or changes to insurance records should be investigated promptly.
Healthcare organizations should also maintain processes through which patients can dispute incorrect information and request corrections where identity misuse is suspected. Resolving medical identity theft can involve insurers, providers and record systems, making early detection particularly important.
The five-month investigation period demonstrates a common challenge
The incident occurred in December 2025, while the review reportedly confirmed the potential exposure of Everside Health information on May 26, 2026. This gap illustrates the time required to investigate complex healthcare data breaches.
Determining that unauthorized access occurred is often only the beginning. Investigators may need to identify which servers and storage locations were affected, reconstruct attacker activity and manually review large numbers of documents to determine whose information they contained.
This process can be especially difficult when archived files are unstructured, inconsistently named or spread across different customer environments. Organizations may know that data was accessed while still being unable to determine immediately which individuals were affected.
The delay also means that exposed information may have been available to attackers for several months before affected individuals received notice. During that period, fraudulent activity may occur without victims understanding that their information has been compromised.
Organizations should therefore invest in accurate data inventories and classification systems before an incident occurs. Knowing which files contain health records, Social Security numbers and other sensitive information can significantly improve breach assessment and notification.
Data discovery must precede effective protection
Healthcare organizations cannot protect information effectively unless they know what they hold, where it is stored, who can access it and which vendors receive copies.
Sensitive information may exist in clinical systems, cloud storage, document archives, email attachments, scanned forms, backup environments and temporary migration repositories. A primary database may be well protected while exported files remain accessible through less closely monitored systems.
Data classification should identify records containing protected health information, Social Security numbers, insurance information and other sensitive categories. Controls can then be applied according to the potential harm associated with exposure.
Highly sensitive archives should receive strong encryption, restricted permissions, detailed access logging and monitoring for bulk downloads. Copies should not be created without a defined business purpose and approved retention period.
Organizations should also ensure that migration projects do not leave forgotten datasets in temporary staging environments after the work has been completed. Temporary copies have an impressive habit of becoming permanent liabilities once the project team moves on to something more exciting.
Least privilege can reduce the scale of a breach
Access to archived healthcare information should be limited to users and services that genuinely require it. Broad access granted for operational convenience increases the number of accounts that attackers can target.
Administrative users should have separate privileged accounts protected with strong multi-factor authentication. Service accounts should receive only the permissions required for their specific tasks and should not share credentials across unrelated systems.
Cloud permissions should be reviewed regularly to identify unused accounts, excessive roles and long-lived access keys. Former employees, contractors and completed migration projects should not retain access indefinitely.
Least privilege may not prevent every initial compromise, but it can restrict how much information an attacker can reach after gaining access to one account or workload.
Vendor personnel should also access customer data only when necessary. Access should be time-limited, approved and recorded rather than provided continuously through standing administrative privileges.
Encryption must include strong key protection
Sensitive healthcare archives should be encrypted both while stored and while transferred between systems. However, encryption provides limited protection if attackers can access the data through a legitimate application or obtain the associated encryption keys.
Keys should be managed separately from the encrypted data and protected through tightly controlled key-management systems. Access to keys should be logged and limited to approved services and administrators.
Organizations should also understand whether encryption is applied at the storage layer, application layer or individual file level. These approaches protect against different threats and should not be treated as interchangeable.
Storage encryption may protect physical media and snapshots, while application-level controls can help restrict access even when the storage environment itself is reachable. Highly sensitive information may require additional file-level protection.
Encryption is an important layer, but it does not replace identity security, monitoring or least privilege. Data that an attacker can access through a compromised authorized account may be decrypted normally by the same systems designed to serve legitimate users.
Cloud logs must be centralized and retained
Cloud environments can generate detailed records of authentication, file access, administrative changes and network activity. These logs are essential for determining how attackers entered, what they accessed and whether they retained access.
Logs should be forwarded to a centralized security platform where they cannot easily be altered through compromise of the affected account or workload. Retention periods must be long enough to support investigation when an incident remains undetected for several months.
Security teams should alert on unusual administrative activity, large file downloads, access from new geographic locations and attempts to disable logging. Changes to cloud roles, access policies and credentials should also receive scrutiny.
Vendor environments should provide customers with sufficient evidence during an incident. Healthcare organizations need contractual and practical access to the information required to assess their own reporting and notification obligations.
A contract promising cooperation is not particularly useful when the vendor cannot produce the relevant logs or discovers that default retention deleted them before anyone realized they mattered.
Vendor agreements need enforceable security requirements
Healthcare organizations should require vendors handling protected health information to meet clearly defined security standards. Agreements should specify requirements for authentication, encryption, logging, vulnerability management, data retention and incident notification.
Vendors should also disclose whether subcontractors or additional cloud services process the information. Each additional organization creates another trust relationship and potential route to the data.
Incident-notification clauses should establish how quickly the healthcare organization must be informed after suspicious activity is discovered. Delayed notification can prevent the organization from investigating connected systems and warning affected individuals promptly.
Contracts should also address evidence preservation, forensic cooperation and secure deletion when the relationship ends. The organization should be able to confirm that archived and migration data has been removed from vendor systems when it is no longer required.
Independent security assessments and compliance certifications can provide useful assurance, but they should not replace continuous oversight. A certification reflects conditions at a particular point in time and does not guarantee that every cloud identity, application integration and storage location will remain secure.
Third-party concentration should be understood
A healthcare data migration and archiving provider may store information for multiple healthcare organizations. This creates concentration risk because one vendor compromise can affect patients associated with several separate customers.
Attackers increasingly target service providers for precisely this reason. Compromising one environment may provide access to datasets belonging to many organizations without requiring individual attacks against each healthcare provider.
Customers should understand how their data is separated from other clients, whether administrative identities cross customer boundaries and whether a compromise within one tenant could expose another.
Vendors should implement strong tenant isolation, separate encryption contexts and customer-specific access controls. Shared administrative accounts and broadly accessible storage environments can transform a limited compromise into a multi-customer breach.
Healthcare organizations should also avoid assuming that a vendor’s size or specialization guarantees security. Specialist providers may understand healthcare workflows well while still facing the same identity, configuration and monitoring risks affecting every cloud environment.
Incident response must include vendor compromises
Healthcare incident-response plans should address breaches occurring within third-party environments rather than focusing only on internal systems.
The plan should identify who contacts the vendor, how logs will be obtained, how affected datasets will be identified and how regulatory obligations will be coordinated. Legal, privacy, clinical, communications and cybersecurity teams may all need to participate.
Organizations should maintain an accurate list of vendors holding protected health information and know which internal owner manages each relationship. Discovering during an incident that nobody knows which department approved the service is not an especially promising beginning to forensic coordination.
The organization should also determine whether compromised vendor credentials or integrations provide access back into its own environment. API keys, file-transfer accounts and trust relationships may need to be disabled or rotated.
Response exercises should include realistic third-party scenarios in which the healthcare organization does not control the affected systems and must depend on another company for evidence and remediation.
Affected individuals require long-term protection
Aesto is offering affected individuals identity and credit-monitoring services. Such services can help identify new credit accounts or suspicious identity activity, but they cannot prevent every form of misuse involving health information.
Affected individuals should monitor credit reports, financial accounts, health insurance statements and medical bills. They should also remain alert for communications that use personal or medical details to appear legitimate.
A credit freeze can provide stronger protection against fraudulent credit applications than monitoring alone because it restricts access to the individual’s credit file. Fraud alerts may also require lenders to take additional verification steps.
Individuals should use strong, unique passwords and multi-factor authentication for email, financial and healthcare accounts. Email security is particularly important because attackers may use access to reset passwords for other services.
Security precautions should continue beyond the complimentary monitoring period. Social Security numbers and medical history do not expire after one or two years, and attackers may delay using stolen information until attention surrounding the breach has diminished.
The broader cybersecurity lesson
The Everside Health breach demonstrates that healthcare data remains vulnerable wherever it travels, including cloud migration platforms and archival systems operated by third parties.
Security cannot stop at the healthcare provider’s network boundary. It must follow sensitive information through every vendor, cloud environment, backup and temporary processing location.
The incident also shows why archived data must receive the same protection as actively used clinical information. Records stored for historical, compliance or migration purposes remain valuable to criminals and harmful when exposed.
Organizations need accurate data inventories, strict retention policies, least-privilege access, centralized cloud logging, strong encryption and continuous third-party oversight. Vendor relationships must include enforceable requirements for incident notification, forensic cooperation and secure deletion.
Most importantly, healthcare organizations should plan for the possibility that a trusted provider will eventually be compromised. Trust does not remove risk; it merely changes where the risk is located.
The infrastructure involved in this incident belonged to a third-party vendor, but the exposed information still related to Everside Health patients. For those individuals, the distinction between direct and indirect compromise offers little comfort because their Social Security numbers and health records face the same potential misuse.
Organizations must therefore protect information according to its sensitivity rather than its location or ownership. Once protected health information leaves the primary healthcare environment, it should not become less visible, less monitored or less secure.
A vendor may provide migration and archival services, but cybersecurity responsibility must travel with the data. Otherwise, the organization may discover that its most carefully protected records became exposed through the external system entrusted to preserve them.

Data breach at Everside Health may have exposed names, SSNs, and health records. Check if you're affected and take action.
Source: Everside Health Data Breach Exposes Social Security Numbers via claimdepot.com.
Was this article helpful?
Your feedback helps us improve the knowledge base.