Graham County Hospital
ent_fff0df1f8ad765f2f592a742
Disclosures
2
State AG · 2 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1
as filed · State AG NH
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Graham County Hospital
- Normalized
- graham county hospital— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- New Hampshire State AGas victim2026-09-11
Graham County Hospital notified the NH Attorney General of a data security incident involving its third-party vendor, Aesto, LLC. Unauthorized access to patient data occurred between December 2 and December 18, 2025. GCH became aware of the incident on June 26, 2026. One New Hampshire resident was affected, with potential exposure of name, date of birth, and Social Security Number. GCH offered 12 months of credit monitoring.
- Massachusetts State AGas victim2026-09-01
Aesto, LLC, a healthcare data migration and archiving service provider, experienced a cyber incident affecting its AWS infrastructure between December 2 and December 18, 2025. The incident was discovered on December 18, 2025. Forensic analysis confirmed that an unauthorized actor accessed and potentially acquired protected health information (PHI), including names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, ITINs, and Social Security numbers, for individuals affiliated with Graham County Hospital and other covered entities. Aesto engaged external cybersecurity professionals, secured the network, reset credentials, and deleted impacted Lambda functions and unauthorized files. No evidence of data misuse was found. Aesto notified covered entities on June 26, 2026, and offered to notify HHS OCR on their behalf.