Patients whose records flowed through a healthcare data migration and archiving vendor are at the center of a breach notification filed with New Hampshire regulators.
Health Access Network told the state attorney general that the protected health information of its patients was caught in a security incident at Aesto LLC, a business associate that handles data migration and archiving services. The exposure window ran from December 2 to 18, 2025.
Full names, Social Security numbers, and medical information were affected, according to the notification. Class action attorneys have opened an investigation into the incident.
The case fits a pattern that has defined healthcare breaches for years: the covered entity keeps its name out of the headlines while a smaller vendor absorbs the risk. Business associates now account for a large share of reported incidents, and the fallout lands on patients who never chose the vendor.
For compliance teams, the takeaway is about the contracts behind the systems. Data migration and archiving vendors often hold full record sets in searchable form, and moving that data is exactly when access controls slip. Reviewing business associate agreements for breach-notification timelines, encryption requirements, and deletion schedules is the practical next step.