The incident centers on Aesto, a healthcare data migration service that processed information for Health Access Network. Forensic analysis indicates that unauthorized activity took place within Aesto's AWS environment between December 2 and December 18, 2025. Although Aesto identified the security lapse on December 18, Health Access Network was not informed of the breach until July 2026. Official notification letters to affected residents in New Hampshire began circulating on September 17, 2026.
Edelson Lechtzin LLP is now evaluating potential class action litigation. The firm claims that exposed data may include full names, Social Security numbers, and specific medical records, placing victims at heightened risk for identity theft and fraud. While affected individuals have been offered identity monitoring services via Kroll, the legal team is seeking to recover damages for lost time and privacy violations. Patients who received breach notices are encouraged to secure their financial records and preserve all correspondence related to the incident while the investigation proceeds.




Comments (0)
No comments yet. Be the first!