Aesto vendor breach reaches two more health centers in NC and Maine
Issue
Breach letters posted by Massachusetts regulators on September 18 and 25, 2026 show the Aesto data-archiving breach reached Ocracoke Health Center in North Carolina and Health Access Network in Maine. Neither appears on Aesto's own list of affected clients, last updated September 8.
Any health center that used Aesto to archive an old EHR should ask the vendor directly.
Sources for this story
Massachusetts Office of Consumer Affairs and Business Regulation (breach letters 2026-1569 and 2026-1608)Sources for your board packet
This story's source plus 4 related stories and their sources, ready to print for your team or board.
Free. Unlocking the packet subscribes you to Intel Brief. You'll be subscribed right away, with no confirmation email. Unsubscribe with one click in any issue. If you unsubscribed before, we won't re-add you. We never sell your email. You can open each source above without an email.
Part of
- Enforcement: privacy, fraud and audits
Data breaches
FQHC Talent. (2026, September 18). Aesto vendor breach reaches two more health centers in NC and Maine. Source: Massachusetts Office of Consumer Affairs and Business Regulation (breach letters 2026-1569 and 2026-1608). Retrieved October 6, 2026, from https://www.fqhctalent.com/intel/aesto-breach-letters-ocracoke-health-access-network-september-2026
More in Risk & Compliance
Sep 29
HHS civil rights office says when states can use substance use records
Sep 25
CMS and 37 states pledge to judge Medicaid by health outcomes
Sep 24
Geiger Gibson review finds health centers expect a heavy work-rule frailty burden
Sep 24
CMS seeks input on Part D pharmacy contract terms, including 340B claims