Skip to main content
Jump to a category page

Graham County Hospital, a critical-access hospital in Hill City, Kansas, has notified patients that their Social Security numbers and dates of birth were exposed in a breach at a data-management vendor — a vendor breach that has now affected 9.5 million people at hospitals across the country.

Graham County Hospital mailed individual notice letters to affected patients on September 14, 2026, confirming that patient data was exposed in a data security incident at Aesto, LLC, a Birmingham, Alabama company that provides healthcare data migration and archiving services. Aesto experienced unauthorized access to a portion of its Amazon Web Services infrastructure between approximately December 2 and December 18, 2025. Aesto confirmed on May 26, 2026 that patient information had been accessed, and began notifying its hospital and healthcare provider clients — including Graham County Hospital — on or around June 26, 2026. Graham County Hospital’s own regulatory filings confirm Social Security numbers and dates of birth were involved.

Source: Graham County Hospital’s own Massachusetts Office of Consumer Affairs and Business Regulation filing (2026-1556); New Hampshire Department of Justice notification letter, filed by Wilson Elser on Aesto’s behalf, dated 09/11/2026; individual patient notice mailed 09/14/2026.

A Vendor Breach Affecting 9.5 Million People Nationwide

Aesto’s data security incident is not limited to Graham County Hospital. According to Aesto’s own reporting to the U.S. Department of Health and Human Services, the breach affects approximately 9,540,683 individuals across numerous hospitals and healthcare providers nationwide, making it one of the largest healthcare data breaches reported this year. The information Aesto held on behalf of its healthcare clients reportedly included full names, dates of birth, medical information, driver’s license numbers, financial account numbers, health insurance information, Social Security numbers, and other government identification numbers.

Source: HIPAA Journal and BleepingComputer reporting on Aesto Health’s breach disclosure and its submission to the HHS Office for Civil Rights breach portal (9,540,683 individuals).

A Long Chain From Breach to Notice

The timeline here runs through several steps, and each one adds delay. Aesto’s intrusion window closed on December 18, 2025. Aesto didn’t notify Graham County Hospital until June 26, 2026 — roughly 190 days later. Graham County Hospital then mailed individual notice to patients on September 14, 2026. Measured from the original incident to the patient notice letter, that’s approximately 270 days. The largest single gap in that chain is the nearly seven months between Aesto’s own breach and the point when it told its hospital clients about it.

Lawsuits Already Filed Against Aesto

Multiple lawsuits have already been filed against Aesto, LLC in the U.S. District Court for the Northern District of Alabama over this breach, including Jackson v. Aesto, LLC (No. 2:26-cv-01338), Sibthorpe v. Aesto, LLC (No. 2:26-cv-01367), Nguyen v. Aesto, LLC (No. 2:26-cv-01373), McDaniel v. Aesto, LLC (No. 2:26-cv-01547), Chalmers v. Aesto, LLC (No. 2:26-cv-01553), and Doe v. Aesto, LLC (No. 2:26-cv-01549) — all a matter of public court record.

What Information Was Exposed at Graham County Hospital?

Graham County Hospital’s own regulatory filings confirm the following categories for its patients:

  • Social Security number
  • Date of birth

This is narrower than the full list of categories reported across the broader Aesto breach, but it is independently confirmed on Graham County Hospital’s own filing — not just inferred from the vendor’s disclosure.

Do You Have Legal Options?

Healthcare providers have a legal duty to ensure that the vendors they trust with patient data secure it properly and disclose incidents without unreasonable delay — and that duty doesn’t disappear just because a third-party vendor was the one that got breached.

If you received a notice letter naming Graham County Hospital and Aesto, contact Emery | Reddy today for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

FAQ

Who is affected by the Graham County Hospital data breach?

Patients of Graham County Hospital whose information was stored on the network of Aesto, LLC, a third-party data migration and archiving vendor. Graham County Hospital mailed individual notice letters on September 14, 2026.

What information was exposed?

Graham County Hospital’s own filings confirm Social Security numbers and dates of birth. The broader Aesto breach, affecting other hospitals nationwide, has also involved medical information, driver’s license numbers, and financial account data.

Is this the same breach affecting other hospitals?

Yes. Aesto, LLC’s data security incident affected numerous hospitals and healthcare providers across the country, totaling approximately 9.5 million people according to Aesto’s own reporting to federal regulators. Graham County Hospital is one of the affected covered entities.

Why did it take so long to notify patients?

Aesto’s breach occurred in December 2025, but it didn’t notify Graham County Hospital until June 2026 — about 190 days later. Graham County Hospital then mailed patient notices in September 2026, for a total gap of roughly 270 days from the original incident.

Has a lawsuit already been filed?

Yes. Multiple lawsuits have been filed against Aesto, LLC in the Northern District of Alabama over this breach, including Jackson v. Aesto, Sibthorpe v. Aesto, Nguyen v. Aesto, McDaniel v. Aesto, Chalmers v. Aesto, and Doe v. Aesto.

Do I have a legal claim?

Healthcare providers have a legal duty to ensure that the vendors handling patient data secure it properly and disclose incidents without unreasonable delay. If you received a notice letter naming Graham County Hospital and Aesto, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now