Everside Health Data Breach Investigation

Data Breach Blog

Data Breach

Everside Health Data Breach Investigation

Almeida Law Group Calendar Icon

Date of data breach:

July 31, 2026

by: Almeida Law Group

Almeida Law Group is investigating a data breach at Everside Health. The breach occurred on December 2nd, 2025. If you were affected, contact Almeida Law Group.

About Everside Health

Everside Health was a Denver, Colorado-based direct primary care provider that operated more than 375 health centers across 34 states, delivering primary care, mental health, and occupational health services to employers and unions. Everside merged with Marathon Health in 2024 and now operates under that name. The breach at issue did not occur within Everside Health’s own systems. It occurred at Aesto, LLC (doing business as Aesto Health), a Birmingham, Alabama-based healthcare data migration and archiving vendor that served as a business associate of Everside Health. Aesto provides a SaaS platform for migrating, archiving, and accessing HIPAA-compliant data from legacy electronic health record systems.

What Happened?

Everside Health was listed in a California Attorney General sample breach notice in connection with a network security incident at its vendor, Aesto Health. According to Aesto Health’s own public notice dated June 24th, 2026, on December 18th, 2025, Aesto experienced a security incident affecting a limited portion of its Amazon Web Services infrastructure. After a forensic investigation and manual document review, Aesto confirmed on May 26th, 2026, that between approximately December 2nd, 2025, and December 18th, 2025, protected health information stored on Aesto’s network may have been accessed and acquired by an unauthorized actor. Aesto notified Everside Health of the incident on June 26th, 2026—more than six months after the incident began—and consumer notifications followed in late July 2026.

Aesto’s public notice lists the data types potentially involved across all affected clients as full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, and Social Security numbers, with the specific elements varying by individual. The California Attorney General notice for Everside Health uses a template placeholder rather than identifying the precise data types exposed for Everside Health patients specifically. No ransomware group has claimed responsibility for this incident. Separately, Aesto has a prior breach history: in 2022, the company experienced unauthorized access to its systems between December 25th, 2021, and March 8th, 2022, resulting in the exfiltration of radiology reports belonging to approximately 17,400 patients of Osceola Medical Center in Wisconsin. The law firm Pittman, Dutton, Hellums, Bradley & Mann, P.C. has announced active investigations into the December 2025 Aesto breach on behalf of patients at multiple affected covered entities, though no class action complaint specific to Everside Health patients has been filed as of the time of this writing.

Key Facts at a Glance

  • Company or Organization: Everside Health (breach occurred at vendor Aesto Health)
  • Industry: Healthcare / Direct Primary Care (Everside Health); Health IT / Healthcare Data Migration and Archiving (Aesto Health)
  • Location: Everside Health: Denver, Colorado (now operating as Marathon Health, Indianapolis, Indiana). Aesto Health: Birmingham, Alabama
  • Incident type: Unauthorized access to and potential acquisition of protected health information stored on vendor’s Amazon Web Services infrastructure
  • Date of breach: December 2nd, 2025
  • Date breach discovered: December 18th, 2025
  • Date of consumer notification: July 31st, 2026
  • Identity theft protection offered: Complimentary Privacy Solutions ID membership through Epiq
  • Prior breach: Aesto Health experienced a prior breach in 2022 involving unauthorized access from December 25th, 2021, through March 8th, 2022, affecting approximately 17,400 Osceola Medical Center patients
  • Litigation status: Active attorney investigations announced by Pittman, Dutton, Hellums, Bradley & Mann, P.C. on behalf of patients at multiple covered entities affected by the Aesto breach; no filed class action specific to Everside Health patients identified at this time
  • Source: California Attorney General sample breach notice (https://oag.ca.gov/ecrime/databreach/reports/sb24-627495); Aesto Health public notice (https://www.aestohealth.com/notice-of-data-security-incident-12-18-25/); TechTarget (https://www.techtarget.com/healthtechsecurity/news/366594775/Aesto-Health-Aon-PLC-Alameda-Health-System-Suffer-Healthcare-Data-Breaches); HIPAA Journal (https://www.hipaajournal.com/data-breaches-reported-by-aesto-health-and-motion-picture-industry-health-plan/); Pittman Dutton (https://www.pittmandutton.com/firm-news/together-womens-health-medical-group-of-alabama-data-breach)

What Should You Do?

If you received a notice about this breach, enroll in the complimentary Privacy Solutions ID membership offered through Epiq before your enrollment deadline, using the activation code included in your letter. Visit www.privacysolutionsid.com to get started. You should also consider placing a fraud alert or credit freeze on your files with the three major credit bureaus—Equifax, Experian, and TransUnion—to reduce the risk of new accounts being opened in your name. Monitor your credit reports regularly; you can request free reports at AnnualCreditReport.com. Because health information was involved in this incident, review your Explanation of Benefits statements and any medical records for services you do not recognize, and report any suspicious activity to your insurer. If you suspect your information has already been misused, visit IdentityTheft.gov for step-by-step guidance on recovering from identity theft.

Your Legal Rights

If your personal or health information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.

Were You a Victim of a Data Breach?

"*" indicates required fields

By clicking the SEND button and submitting this form, I consent to receive communications from Almeida Law Group LLC and their co-counsel by phone call, email, and/or SMS regarding this matter and other potential legal matters. I understand that message and data rates may apply and that consent to such contact is not required for use of these services. Message frequency varies. Reply STOP to opt-out and HELP for help. I also agree to the Privacy Policy. I understand that my information may be shared with advertising partners to deliver targeted advertisements and optimize outreach efforts. I confirm that I am at least 18 years old. I have read and understand the disclaimer above. I agree my use of this site and the information provided here is not intended to create and does not create an attorney client relationship with the Almeida Law Group and/or attorneys employed by the Firm. No attorney client relationship is intended or created unless and until an engagement agreement is signed by all relevant parties. The contents of this site constitute attorney advertising and not legal advice; therefore you should not act or rely upon any information contained herein, and should always seek the advice of an attorney.

Resourceful. Resilient. Relentless.

Contact us today to get the justice you and your family deserve.