Livara Health Medical Group, P.C., which operates as SpineZone, is a San Diego-based physical therapy and spine care practice serving patients throughout California. SpineZone recently notified patients that a security incident at Aesto, LLC, a third-party vendor that provides data migration and archiving services for the practice, may have exposed some of their personal information.
Healthcare providers and the vendors they rely on to manage patient records take on a responsibility to keep that information secure, and when a vendor-side incident puts patient data at risk, the people affected are the ones left to deal with the fallout.
SpineZone’s Data Breach Investigation
Data breach attorneys are looking into a security incident disclosed by Livara Health Medical Group, P.C., the physical therapy and spine care practice that operates under the SpineZone brand across San Diego County and other parts of California. According to a notice filed with the California Attorney General’s office, the incident did not originate inside SpineZone’s own systems. Instead, it happened at Aesto, LLC, a third-party company that provides healthcare data migration and archiving services for SpineZone and other medical practices.
Aesto reported that it experienced a network security incident affecting a limited portion of its Amazon Web Services infrastructure. After being alerted to the issue, Aesto worked with outside cybersecurity professionals to investigate what had happened and which files may have been affected. Following an extensive forensic investigation and a manual review of the documents involved, Aesto determined that an unauthorized actor may have accessed and acquired protected health information belonging to SpineZone patients that Aesto was storing on its network.
This type of arrangement, where a healthcare provider outsources data storage, migration, or archiving to an outside technology vendor, is extremely common. It allows practices like SpineZone to focus on patient care while relying on specialized companies to manage the technical side of records retention. But it also means that a single vulnerability at one vendor can put patient information from many different provider practices at risk at the same time, since the vendor typically stores data on behalf of numerous clients rather than just one. When something goes wrong at that level, the practices themselves, and their patients, often only learn about it well after the fact, once the vendor completes its own investigation and passes the information along.
Aesto has stated that it has no evidence that any of the information involved in this incident has actually been misused for identity theft or fraud. That is a common statement in early breach notifications, since it can take months or years for stolen data to surface in a fraud scheme, and companies typically only have visibility into confirmed cases of misuse, not the full universe of what may eventually happen to compromised information. Patients are being offered a complimentary twelve-month membership in credit monitoring and identity theft protection services as a precaution.
Data breach attorneys who take on cases like this one typically look at several questions: whether Aesto and SpineZone maintained reasonable safeguards for the sensitive health information they were storing, whether the notification process moved quickly enough once the incident was discovered, and whether patients were given clear, complete information about what happened to their records. Vendor-side incidents like this one raise an additional question that attorneys often examine closely: how carefully the healthcare provider vetted the third-party vendor’s own security practices before entrusting it with patient data in the first place.
Breaches involving protected health information carry particular risk because medical records and the identifying information tied to them cannot simply be replaced the way a credit card number can. Stolen identifying information tied to a patient record can be used for years to attempt fraudulent medical billing, apply for credit, or impersonate the victim in other ways, which is part of why healthcare data is considered especially valuable on the black market and why healthcare-adjacent vendors like Aesto have increasingly become a target for cybercriminals.
Because Aesto serves as a data vendor for multiple healthcare practices, not just SpineZone, this incident is a reminder that patients can be affected by a breach even when the provider they see in person was not the one whose systems were directly compromised. Regulators and plaintiffs’ attorneys pay close attention to these vendor-level incidents for exactly this reason: a single point of failure at a shared technology or data-management vendor can expose far more people than a breach confined to one office would, and it can take longer for those affected to even learn that their own provider was involved.
This investigation remains ongoing, and additional details about the scope of the incident, including a full accounting of how many patients were affected nationwide, may become available as Aesto, SpineZone, or state regulators release further information, or as the matter proceeds through litigation and discovery.
When Did This Breach Occur?
According to Aesto’s notification letter, the underlying security incident took place on or about December 18, 2025, when Aesto detected unauthorized activity affecting a portion of its Amazon Web Services infrastructure. Aesto’s subsequent forensic investigation determined that an unauthorized actor may have accessed and acquired certain files between on or about December 2, 2025, and December 18, 2025. Aesto completed its investigation and confirmed the scope of the incident on May 26, 2026, roughly five months after the intrusion was first detected. Aesto informed SpineZone of the incident on June 26, 2026, and SpineZone, through Aesto, began sending notification letters to affected patients on August 25, 2026. The gap between detection and patient notification, several months in this case, is not unusual for incidents that require an extensive forensic review to determine exactly whose information was involved, but it does mean that some affected individuals may not have learned their information was at risk until well after the incident itself occurred.
What Information Was Breached?
Aesto’s notification letter states that the information potentially involved included patients’ full names, along with other personal information that Aesto held as part of the archiving and data migration services it performs for SpineZone. The letter specifies that the incident did not involve patients’ mental or physical condition, treatment details, or medical history. Aesto has not publicly released a complete, itemized list of every data element involved for all affected individuals, and the exact categories of information exposed may vary by patient depending on what records Aesto was storing on SpineZone’s behalf. Anyone who received a direct notification letter should review it closely, since it should identify the specific categories of their own information that were involved. Aesto states it has no evidence that any of the information has been misused for identity theft or fraud as of the date of the notice, though it is offering twelve months of complimentary credit monitoring and identity theft protection through TransUnion as a precaution.
What You Can Do
If you received a notice that your information was involved in the SpineZone data breach, consider taking the following steps:
- Read your notification letter carefully and keep a copy for your records, including the enrollment code for credit monitoring.
- Enroll in the complimentary twelve-month TransUnion credit monitoring and identity theft protection membership offered in the notice.
- Place a fraud alert or a credit freeze with Equifax, Experian, and TransUnion.
- Review your financial accounts, insurance statements, and credit reports regularly for unfamiliar activity.
- Be cautious of unsolicited calls, texts, or emails asking you to verify personal or medical information, since scammers sometimes pose as a breached company or its monitoring service.
- Keep any documentation related to the incident in case you need it to support a legal claim.
File a Data Breach Lawsuit Against SpineZone
If your personal information was exposed because of this incident at Aesto, LLC, you may have legal options against SpineZone, Aesto, or both. Companies that collect and store sensitive health information, along with the vendors they trust to manage that data, have a responsibility to keep it secure, and when that responsibility is not met, the patients affected deserve accountability.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.