Graham County Hospital
bd_552342ca92f19318 · schema v1 · pii pii-v2
Full breach record for Graham County Hospital →Aesto, LLC, a healthcare data migration and archiving service provider, experienced a cyber incident affecting its AWS infrastructure between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Forensic analysis confirmed that an unauthorized actor accessed and potentially acquired protected health information (PHI), including names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, ITINs, and Social Security numbers, for individuals affiliated with Graham County Hospital and other covered entities. Aesto engaged external cybersecurity professionals, secured the network, reset credentials, and deleted impacted Lambda functions and unauthorized files. No evidence of data misuse was found. Aesto notified covered entities on June 26, 2026, and offered to notify HHS OCR on their behalf.
J jump to incidentP pin to compareR raw source
Incident timeline
Dec 2, 2025
Begins
Dec 18, 2025
Discovered
Sep 1, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- New Hampshire State AGbd_6f94ad8afcd0294b2026-09-11 · +10dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Sep 1 (MA), last Sep 11 (NH) — a 10-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.