A vendor that archives the EHR you decommissioned was breached — at least seven health centers are affected, and its own client list is provably incomplete
Aesto Health migrates and archives patient data when a health center replaces its EHR. Its notice says the incident occurred "between on or about December 2, 2025, and December 18, 2025," was confirmed May 26, 2026, posted publicly June 24, and client notification began June 26 — with individual notifications landing from August 21.
Data elements listed include names, dates of birth, medical information, driver's license numbers, financial account numbers, health insurance information, taxpayer identification numbers, government identification numbers, and Social Security numbers for a limited subset. THE FQHC FOOTPRINT, read off Aesto's own covered-entity page (stamped "Updated: 9-3-2026"): six confirmed health centers are named — Midtown Community Health Center (UT), Monroe Health Center (WV), Marana Health / MHC Healthcare (AZ), Park West Health Systems (MD), Sterling Health Solutions (KY), and Shenandoah Valley Medical System (WV). 🔑 BUT THAT LIST IS NOT COMPLETE.
Kaniksu Community Health, an Idaho FQHC, is not on Aesto's page — yet its own breach-notification letter, filed with the California Attorney General, states: "Kaniksu Community Health (‘Kaniksu’) learned of a data incident involving Aesto, LLC, (‘Aesto’) a healthcare data management a service provider to Kaniksu" [sic]. So the real count is at least seven, and a health center should not treat absence from the vendor's list as evidence it was unaffected.
WHY THIS ONE IS DIFFERENT FROM AN ORDINARY BREACH: Aesto's business is holding the system you retired. That means the exposed data often sits somewhere IT no longer counts as live and that may sit outside the current HIPAA Security Rule risk analysis.
Any center that has switched EHRs — an OCHIN Epic migration, an eClinicalWorks conversion, a practice acquisition — should ask this week who holds its legacy archive, whether a current business associate agreement covers it, and whether that archive is inside the risk analysis. The notification lag is its own finding: roughly 190 days from incident to covered-entity notice, far outside the 60-day ceiling in 45 CFR 164.410.
TWO LIMITS ON THE NUMBERS. The widely reported figure of 9,540,683 affected individuals is attributed to OCR by trade press and is not confirmed against the federal breach portal, so treat it as reported rather than established.
Trade coverage also described Mineral Community Hospital and Holton Community Hospital as community health centers; both are hospitals, and the underlying list is a 340B covered-entity roster, which spans FQHCs, look-alikes and several hospital categories — it is not an FQHC roster. One organization, Lone Star Community Health Center, was listed as affected by one outlet but does not appear on Aesto's page.
Separately and unrelated to Aesto, Boston Health Care for the Homeless Program — an FQHC funded under section 330(h) — sent its own breach letter dated August 7, 2026 for a direct network intrusion discovered June 8, 2026 that traces to a disruption first learned of November 11, 2025.
Key takeaways
- Ask this week who holds your legacy EHR archive, whether a current BAA covers it, and whether it is inside your HIPAA risk analysis — decommissioned systems are the exposure here.
- Do not treat absence from a vendor's published client list as evidence you were unaffected — Kaniksu Community Health is confirmed affected and is not on Aesto's list.
- Roughly 190 days elapsed from incident to covered-entity notice, well past the 60-day ceiling in 45 CFR 164.410 — a business associate's delay becomes your notification problem.
Source packet
This story's linked evidence + 4 related tracked stories with theirs — one print-ready digest for your team or board packet.
Free — unlocks the packet and submits a single opt-in for Intel Brief. Eligible addresses are subscribed immediately and no confirmation email is sent; a prior unsubscribe, verified deletion, or bounce is not overridden. Individual sources are always clickable above, no email needed.
FQHC Talent. (2026, August 21). A vendor that archives the EHR you decommissioned was breached — at least seven health centers are affected, and its own client list is provably incomplete. Linked evidence: Aesto Health covered-entity notice (Updated 9-3-2026); Kaniksu Community Health breach letter filed with the California Attorney General (sb24-629145). Retrieved September 11, 2026, from https://www.fqhctalent.com/intel/aesto-health-vendor-breach-fqhc-legacy-archive-2026
More in Risk & Compliance
Aug 27
OCR's 55th HIPAA access action adds a current records-request workflow warning
Aug 21
HHS asks clinicians whether federal vaccine-recommendation categories should change — comments due September 20; nothing changes yet
Aug 13
A final rule takes effect October 13 barring federal Medicaid and CHIP payment for a service line more than a dozen tracked health centers advertise — and the age cutoff is different in Medicaid than in CHIP
Aug 11
HRSA publishes the FINAL Health Center Program Scope of Project Policy Manual — effective on release, comment window already ran