CSIDB logo
Incident

Health Access Network, Inc.

Incident posture

Attack window
Dec 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-25 08:34

Linked entities

Victim
Health Access Network, Inc.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Dec 2025
Discovered
Dec 2025
Disclosed
Sep 2026
Resolved
Pending

Summary

Health Access Network patients whose data was handled by Aesto LLC were affected after an unauthorized party accessed a portion of Aesto’s AWS environment, leading to potential exposure of names, Social Security numbers, and medical information. The intrusion was detected by Aesto, later confirmed following a forensic review, and the service provider informed the organization, which then issued breach notices to impacted individuals in New Hampshire and offered identity monitoring. The incident did not involve the organization’s own systems, and a law firm is now examining possible class‑action claims on behalf of those whose information may have been compromised.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

In December 2025, Aesto, LLC detected unauthorized activity within a segment of its Amazon Web Services infrastructure, with the suspicious activity occurring between approximately December 2 and December 18, 2025. The company’s security team identified a network security incident on or about December 18, 2025 and initiated a forensic investigation coupled with manual document review. After completing the investigation, Aesto confirmed on May 26, 2026 that an unauthorized individual may have accessed or acquired certain patient information during that window. Aesto subsequently informed Health Access Network, Inc. of the findings around July 7, 2026.

The potentially exposed data varied by individual and could include full names, Social Security numbers, and medical information belonging to Health Access Network patients whose records were processed by Aesto. Upon receiving the notification from Aesto, Health Access Network reported the incident to the New Hampshire Attorney General and began mailing breach notices to affected New Hampshire residents on September 17, 2026. The notices informed recipients of the possible exposure and indicated that Kroll identity monitoring services were being offered to those whose Social Security numbers were implicated.

In parallel with the notification process, Edelson Lechtzin LLP announced that it was investigating potential class action claims on behalf of individuals whose personal data may have been compromised in the breach, offering free, confidential case evaluations to anyone who had received a breach notice or believed their information was exposed. The law firm’s outreach stated that a successful case could seek compensation for losses such as lost time, out‑of‑pocket costs, and loss of privacy, and could encourage Health Access Network to strengthen its data protection practices. As of September 25, 2026, the incident had been reported to the state attorney general, notices had been distributed, and legal review of possible claims was underway.

Sources

Sources available to members: 1 source.

CSIDB