Everside Health's Patient Records Were Breached. The Intrusion Happened at Its Data Archiving Vendor.
The patient records exposed in the Everside Health breach were sitting on a vendor’s network. Everside had hired that company to migrate and archive healthcare data.
Everside is an employer- and union-sponsored primary care company. The class action firm now investigating the breach describes it as “a direct primary care provider that offers employer- and union-sponsored healthcare services.” The notification letters went out under Aesto’s name, signed “Aesto LLC” and provided on behalf of the covered entities, and the filings naming Everside reached state attorneys general on July 31. The intrusion happened one layer removed from Everside, at Aesto Health, an Alabama company that was storing patient data on Everside’s behalf.
South Carolina’s own breach notice list puts the count in that state at 80,622 residents. The law firm now investigating the incident adds 22,210 Texans and 1,562 people in Massachusetts, figures that have not been checked against those two states’ own filings. Nobody has published a national total, and Everside is one of several Aesto clients caught in the same event.
The vendor category most practices forget they hired
Aesto describes its own business without any marketing gloss: “healthcare data migration and archiving services for its Covered Entity clients.”
Here is what that means in practice. When a clinic retires an EHR, the old charts don’t evaporate. They have to stay reachable for years after the last login, and keeping the dead system licensed and patched that long is expensive and irritating. So the practice pays a company to pull the data out, park it in a searchable archive and shut the old system down.
That company becomes a business associate under HIPAA. What it ends up holding is whatever got copied out of the retired system, which can run to years of chart history. Then the migration invoice clears, and it is easy to never think about it again.
Aesto’s compromised environment held names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, taxpayer identification numbers, other government IDs and Social Security numbers, per the notice on its site. What any given person lost varies. Everside’s patients were not the only ones affected. HIPAA Journal lists Together Women’s Health Medical Group of Alabama among the providers caught in the same event, and reports that Village Practice Management, listed there alongside the names VillageMD and Village Medical, has confirmed more than 25,000 affected patients of its own.
225 days
The timeline is the ugliest part of this.
Aesto says it experienced a security incident affecting part of its Amazon Web Services infrastructure on December 18, 2025. The forensic work took until May 26, 2026 to confirm what had happened: an unauthorized actor may have reached protected health information between roughly December 2 and December 18. Aesto posted its public notice on June 24 and started telling clients on June 26. Everside found out that same day. The breach filings reached state attorneys general on July 31.
That is 225 days from the date Aesto puts on the incident to the date regulators were told. No source says when the letters actually landed in anybody’s mailbox. A vendor-risk writeup at LearnTPRM walks the same timeline and lands on a blunt instruction for anyone keeping a vendor file: “A healthcare data archive is still a high value data store. If a vendor keeps old patient data, the TPRM file should treat that vendor like a sensitive data processor, not as a low risk technology helper.” Ask about access, logging, retention, encryption and breach notice readiness before an incident asks for you.
Aesto’s name is on the incident. The duty to tell patients still sat with Everside, because that is how HIPAA assigns it. A vendor can hold your data, lose your data and still leave you holding the explanation.
Why this lands harder on DPC than on a hospital system
Nothing stops a DPC practice from changing software. No committee, no enterprise contract with four years left on it.
The market is genuinely competitive right now, and the guidance most physicians get is to try things. A doctor might start on Atlas.md, move to Elation Health with Hint Health handling membership billing, then consolidate onto Cerbo or SigmaMD two years later when the stack gets annoying. Each of those moves is a data migration. Each migration leaves a copy of your chart history somewhere you are no longer logging in.
A hospital system has a security officer whose entire job includes tracking that. A solo DPC physician with a panel of 600 has a business associate agreement they signed during a stressful week in 2023 and haven’t opened since.
You might want to go find that agreement. Three questions are worth answering before you close it again: who currently holds data from every system you’ve retired, whether the agreement obligates that vendor to notify you inside a specific number of days rather than whenever forensics wrap up, and whether the archived data still needs to exist at all under your state’s retention clock.
That last one matters more than people expect. Data you have destroyed on schedule cannot be exposed. An archive that nobody has opened since the migration invoice cleared will hold on to everything in it until somebody decides otherwise.
What This Means
For DPC physicians already in practice, this is a paperwork afternoon that pays for itself. Build a list of every vendor that has ever held your patient data, including the ones you fired. Confirm each one is under a current business associate agreement with a hard notification window. Then find out what you are still storing and why.
For physicians evaluating a move into DPC, add one question to your software due diligence. Ask any platform you’re considering what happens to your data if you leave, who performs the export, and where the archive lives afterward. That answer is rarely on a pricing page and it is a fair thing to ask a salesperson.
For the employer-sponsored side of the industry, this is a different kind of problem. Everside merged with Marathon Health in a deal that closed in February 2024, combining roughly 680 health centers across 41 states and about 2.5 million eligible patients. Mergers at that scale generate exactly this kind of legacy archive, because two companies with two technology stacks have to retire one of them. The consolidation wave running through employer primary care right now is quietly manufacturing more of these vendor relationships, not fewer.
Class action firms are already circling. The regulatory filings will keep expanding as more states get their counts. The number that actually matters to a working DPC doctor, though, is the one in your own file cabinet: how many companies are holding your patients’ records today, and when did you last check.