Skip to main content
Jump to a category page

A network security incident at Aesto, LLC, a vendor that stores health records for SpineZone and other healthcare providers, sat undetected for months before patients were told their protected health information may have been exposed.

Livara Health Medical Group, doing business as SpineZone, has notified patients of a data breach that occurred at Aesto, LLC, a vendor that provides healthcare data migration and archiving services to SpineZone and other healthcare organizations. Aesto says it experienced a network security incident on or about December 18, 2025 affecting a limited portion of its Amazon Web Services infrastructure. After an extensive forensic investigation, Aesto confirmed on May 26, 2026 that a limited amount of protected health information stored on its network between December 2 and December 18, 2025 may have been accessed or acquired by an unauthorized actor. Aesto informed SpineZone of the incident on June 26, 2026, and notice letters to patients went out August 25, 2026, the same day SpineZone reported the breach to the California Attorney General.

Source: Aesto, LLC’s own Notice of Data Breach letter; California Attorney General data-breach notification list (reported 08/25/2026, breach dates 12/02/2025 and 12/18/2025).

A Shared Vendor Breach, Not Unique to SpineZone

Aesto, LLC, which also does business as Aesto Health, provides its data migration and archiving services to multiple healthcare providers, not just SpineZone. Independent breach tracking has identified at least one other Aesto client, Everside Health, that separately notified the California Attorney General of patients affected by this same Aesto network incident. That means the total number of people affected across all of Aesto’s healthcare clients is likely larger than the SpineZone-specific patient population alone.

Source: independent breach-tracking coverage of the Aesto, LLC incident (hacknotice.com); California Attorney General filings for Aesto’s other affected healthcare clients.

What Information Was Exposed?

SpineZone’s notice letter confirms the information involved includes each patient’s full name, and states specifically that the exposed information did not include mental or physical condition, treatment, or medical history. The letter’s list of additional exposed data categories was not filled in on the sample notice provided to Emery | Reddy. Independent reporting on the broader Aesto Health incident indicates other affected patients, across Aesto’s various healthcare clients, may have had Social Security numbers, driver’s license or state ID numbers, and dates of birth involved; whether that applies to SpineZone patients specifically has not been independently confirmed.

How Many People Are Affected?

Neither Aesto nor SpineZone has disclosed a total number of affected patients. The only figure in the sample notice reviewed is a Rhode Island-specific disclosure stating approximately 2 Rhode Island residents affiliated with SpineZone may be impacted, a fragment that says little about the total patient population affected nationwide.

What Is Aesto Offering Affected Individuals?

Aesto is offering twelve months of complimentary credit monitoring and identity theft protection services from TransUnion. Affected individuals can enroll at bfs.cyberscout.com/activate using the unique code in their letter and must do so within 90 days of the letter date. Questions can be directed to Aesto’s dedicated response line at 833-918-8060, available Monday through Friday, 8 a.m. to 8 p.m. Central Time.

Your Information Is at Risk

Even a name on its own can be combined with other information circulating from a breach to attempt identity theft or targeted phishing, and if Social Security numbers or driver’s license numbers were involved for some patients, as reporting on the broader Aesto incident suggests, the risk of new-account fraud is significant. Affected individuals should watch financial accounts and insurance statements for unfamiliar activity and enroll in the credit monitoring Aesto is offering.

Do You Have Legal Options?

Vendors that store protected health information on behalf of healthcare providers have a legal duty to secure that data and to notify affected individuals without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter regarding your SpineZone patient information.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.

FAQ

Who is affected by the SpineZone / Aesto data breach?

SpineZone patients whose protected health information was stored on Aesto, LLC’s affected servers. Neither Aesto nor SpineZone has disclosed a total number of affected patients; only a Rhode Island-specific figure of approximately 2 residents appears in the sample notice reviewed.

What information was exposed?

SpineZone’s letter confirms your full name was involved and states specifically that your mental or physical condition, treatment, and medical history were not included. The letter’s list of additional data categories was left blank in the sample provided. Check your own letter for the specific categories that applied to you.

Is this breach specific to SpineZone?

No. The breach happened at Aesto, LLC, a vendor that provides data migration and archiving services to multiple healthcare providers. At least one other Aesto healthcare client, Everside Health, separately notified California regulators about patients affected by this same incident.

Why did it take so long to find out about this breach?

Aesto says the intrusion occurred between December 2 and December 18, 2025, but it did not confirm patient information was involved until May 26, 2026, and did not inform SpineZone until June 26, 2026. Patient notice letters were not sent until August 25, 2026, roughly eight months after the breach window.

Is Aesto offering credit monitoring?

Yes. Aesto is offering twelve months of complimentary credit monitoring and identity theft protection through TransUnion, with enrollment required within 90 days of the letter date.

Do I have a legal claim?

Vendors that store protected health information on behalf of healthcare providers have a legal duty to secure that data and to notify affected patients without unreasonable delay. If you received a notice letter regarding your SpineZone patient information, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now