Were you recently affected by a data breach?

Health Access Network Data Breach

Health Access Network notified New Hampshire regulators of a data breach after its vendor Aesto, LLC suffered a network security incident exposing patients’ Social Security numbers and medical information. Affected individuals may be entitled to compensation.

Health Access Network
Date of Breach: December 2-18, 2025 (incident at business associate Aesto, LLC)
CAU logo

Who was affected:

Clients of Health Access Network

Impacted Data:

Full names, Social Security numbers, and medical information

Health Access Network, Inc. has notified the New Hampshire Attorney General of a data security incident affecting the protected health information of patients whose data was processed by Aesto, LLC, a business associate that provides healthcare data migration and archiving services. Companies entrusted with sensitive medical and financial records have a legal and ethical responsibility to safeguard that information, and when a third-party vendor’s security fails, the patients whose data was exposed can pay the price.

Health Access Network’s Data Breach Investigation

According to a notice filed with the New Hampshire Attorney General’s Office, Aesto, LLC experienced a network security incident on or about December 18, 2025, that impacted a limited portion of its Amazon Web Services (AWS) infrastructure. Aesto detected unauthorized activity and immediately began an investigation, engaging outside cybersecurity experts to determine what personal information, if any, had been accessed.

After an extensive forensic investigation and manual document review, Aesto confirmed on May 26, 2026, that between approximately December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Aesto clients, including Health Access Network, may have been accessed and/or acquired by an unauthorized actor. Health Access Network was notified of the incident by Aesto on or about July 7, 2026. Notably, the incident did not involve unauthorized access to Health Access Network’s own computer systems — the exposure occurred entirely within Aesto’s infrastructure.

Third-party vendor breaches like this one are an increasingly common way for sensitive healthcare data to end up in the wrong hands. Healthcare providers routinely rely on outside companies for services such as data migration, archiving, billing, and IT support, which means a single vulnerability at one vendor can potentially expose the records of patients from many different healthcare organizations at once. Because these vendors often hold data from multiple clients, a breach at one company can cascade into notifications from many unrelated providers months after the original incident occurred.

Healthcare data is a particularly attractive target for cybercriminals because medical records typically combine several pieces of high-value personal information in one place — names, Social Security numbers, dates of birth, and treatment or diagnosis details. Unlike a stolen credit card number, which can be canceled, a compromised Social Security number or complete medical history cannot simply be replaced, giving this type of stolen data long-lasting value on illicit markets for identity theft, medical insurance fraud, and other schemes.

The gap between when a breach is detected and when affected individuals are ultimately notified — here, roughly nine months passed between the incident and the mailed notification letters — is also common in vendor-related incidents, since a forensic investigation must first determine which specific clients and individuals were affected before any client, in this case Health Access Network, can issue its own notice. Health Access Network began notifying the affected New Hampshire residents by first-class mail on September 17, 2026, providing information on protecting against fraud and identity theft along with a toll-free number for questions. Individuals whose Social Security numbers were involved were also offered a complimentary membership in Kroll’s identity monitoring service, which includes credit monitoring, fraud consultation, and identity theft restoration support.

Following the incident, Aesto represented that it contained the breach, remediated the affected environment, reset or rotated affected credentials, and enhanced its monitoring to help prevent similar incidents going forward. Health Access Network has stated that it worked with Aesto to obtain information about the incident and the remediation steps taken.

When Did This Breach Occur?

The underlying incident at Aesto, LLC occurred on or about December 18, 2025, with the window of potential unauthorized access spanning from approximately December 2, 2025, to December 18, 2025. Aesto did not confirm which specific personal information had been affected until May 26, 2026, following an extensive forensic investigation. Health Access Network received notice of the incident from Aesto on or about July 7, 2026, and began mailing notification letters to affected New Hampshire residents on September 17, 2026.

What Information Was Breached?

Health Access Network has disclosed that the information potentially involved includes patients’ full names, Social Security numbers, and medical information. Individuals whose Social Security numbers were affected were offered complimentary identity theft protection services through Kroll. Health Access Network has not indicated that it has evidence the information has been misused, but out of caution is notifying and offering protective services to those affected.

What You Can Do

If you received a breach notification letter from Health Access Network or believe you may have been affected, consider taking the following steps:

  • Enroll in the complimentary Kroll identity monitoring services offered in your notification letter before the stated deadline.
  • Regularly review your medical bills and insurance statements (Explanation of Benefits) for services you did not receive.
  • Monitor your credit reports for unfamiliar accounts or inquiries, and consider placing a fraud alert or credit freeze.
  • Be cautious of unsolicited calls, emails, or texts referencing this breach, which scammers may use to attempt further fraud.
  • Keep any notification letter and related correspondence in case you need to reference it later.

File a Data Breach Lawsuit Against Health Access Network

If your personal or medical information was exposed as a result of this breach, you may have legal options available to you. Companies that collect and store sensitive patient data, whether directly or through third-party vendors, are expected to maintain reasonable safeguards to protect that information.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: September 7-November 7, 2025 (incident at vendor Mercadien, P.C.)
Date of Breach: December 2-18, 2025 (incident at business associate Aesto, LLC)
Date of Breach: Reported to the Vermont Attorney General's Office on September 23, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.