Were you recently affected by a data breach?

SpineZone Data Breach

Livara Health Medical Group, P.C., dba SpineZone, a San Diego-based physical therapy practice, has notified patients that a security incident at its third-party data vendor, Aesto, LLC, may have exposed their personal information. Affected individuals should understand their rights and consider next steps.

SpineZone
Date of Breach: On or about December 18, 2025 (incident window December 2-18, 2025)
CAU logo

Who was affected:

Clients of SpineZone

Impacted Data:

Names, protected health information (specific additional data types not publicly disclosed)

Livara Health Medical Group, P.C., which operates as SpineZone, is a San Diego-based physical therapy and spine care practice serving patients throughout California. SpineZone recently notified patients that a security incident at Aesto, LLC, a third-party vendor that provides data migration and archiving services for the practice, may have exposed some of their personal information.

Healthcare providers and the vendors they rely on to manage patient records take on a responsibility to keep that information secure, and when a vendor-side incident puts patient data at risk, the people affected are the ones left to deal with the fallout.

SpineZone’s Data Breach Investigation

Data breach attorneys are looking into a security incident disclosed by Livara Health Medical Group, P.C., the physical therapy and spine care practice that operates under the SpineZone brand across San Diego County and other parts of California. According to a notice filed with the California Attorney General’s office, the incident did not originate inside SpineZone’s own systems. Instead, it happened at Aesto, LLC, a third-party company that provides healthcare data migration and archiving services for SpineZone and other medical practices.

Aesto reported that it experienced a network security incident affecting a limited portion of its Amazon Web Services infrastructure. After being alerted to the issue, Aesto worked with outside cybersecurity professionals to investigate what had happened and which files may have been affected. Following an extensive forensic investigation and a manual review of the documents involved, Aesto determined that an unauthorized actor may have accessed and acquired protected health information belonging to SpineZone patients that Aesto was storing on its network.

This type of arrangement, where a healthcare provider outsources data storage, migration, or archiving to an outside technology vendor, is extremely common. It allows practices like SpineZone to focus on patient care while relying on specialized companies to manage the technical side of records retention. But it also means that a single vulnerability at one vendor can put patient information from many different provider practices at risk at the same time, since the vendor typically stores data on behalf of numerous clients rather than just one. When something goes wrong at that level, the practices themselves, and their patients, often only learn about it well after the fact, once the vendor completes its own investigation and passes the information along.

Aesto has stated that it has no evidence that any of the information involved in this incident has actually been misused for identity theft or fraud. That is a common statement in early breach notifications, since it can take months or years for stolen data to surface in a fraud scheme, and companies typically only have visibility into confirmed cases of misuse, not the full universe of what may eventually happen to compromised information. Patients are being offered a complimentary twelve-month membership in credit monitoring and identity theft protection services as a precaution.

Data breach attorneys who take on cases like this one typically look at several questions: whether Aesto and SpineZone maintained reasonable safeguards for the sensitive health information they were storing, whether the notification process moved quickly enough once the incident was discovered, and whether patients were given clear, complete information about what happened to their records. Vendor-side incidents like this one raise an additional question that attorneys often examine closely: how carefully the healthcare provider vetted the third-party vendor’s own security practices before entrusting it with patient data in the first place.

Breaches involving protected health information carry particular risk because medical records and the identifying information tied to them cannot simply be replaced the way a credit card number can. Stolen identifying information tied to a patient record can be used for years to attempt fraudulent medical billing, apply for credit, or impersonate the victim in other ways, which is part of why healthcare data is considered especially valuable on the black market and why healthcare-adjacent vendors like Aesto have increasingly become a target for cybercriminals.

Because Aesto serves as a data vendor for multiple healthcare practices, not just SpineZone, this incident is a reminder that patients can be affected by a breach even when the provider they see in person was not the one whose systems were directly compromised. Regulators and plaintiffs’ attorneys pay close attention to these vendor-level incidents for exactly this reason: a single point of failure at a shared technology or data-management vendor can expose far more people than a breach confined to one office would, and it can take longer for those affected to even learn that their own provider was involved.

This investigation remains ongoing, and additional details about the scope of the incident, including a full accounting of how many patients were affected nationwide, may become available as Aesto, SpineZone, or state regulators release further information, or as the matter proceeds through litigation and discovery.

When Did This Breach Occur?

According to Aesto’s notification letter, the underlying security incident took place on or about December 18, 2025, when Aesto detected unauthorized activity affecting a portion of its Amazon Web Services infrastructure. Aesto’s subsequent forensic investigation determined that an unauthorized actor may have accessed and acquired certain files between on or about December 2, 2025, and December 18, 2025. Aesto completed its investigation and confirmed the scope of the incident on May 26, 2026, roughly five months after the intrusion was first detected. Aesto informed SpineZone of the incident on June 26, 2026, and SpineZone, through Aesto, began sending notification letters to affected patients on August 25, 2026. The gap between detection and patient notification, several months in this case, is not unusual for incidents that require an extensive forensic review to determine exactly whose information was involved, but it does mean that some affected individuals may not have learned their information was at risk until well after the incident itself occurred.

What Information Was Breached?

Aesto’s notification letter states that the information potentially involved included patients’ full names, along with other personal information that Aesto held as part of the archiving and data migration services it performs for SpineZone. The letter specifies that the incident did not involve patients’ mental or physical condition, treatment details, or medical history. Aesto has not publicly released a complete, itemized list of every data element involved for all affected individuals, and the exact categories of information exposed may vary by patient depending on what records Aesto was storing on SpineZone’s behalf. Anyone who received a direct notification letter should review it closely, since it should identify the specific categories of their own information that were involved. Aesto states it has no evidence that any of the information has been misused for identity theft or fraud as of the date of the notice, though it is offering twelve months of complimentary credit monitoring and identity theft protection through TransUnion as a precaution.

What You Can Do

If you received a notice that your information was involved in the SpineZone data breach, consider taking the following steps:

  • Read your notification letter carefully and keep a copy for your records, including the enrollment code for credit monitoring.
  • Enroll in the complimentary twelve-month TransUnion credit monitoring and identity theft protection membership offered in the notice.
  • Place a fraud alert or a credit freeze with Equifax, Experian, and TransUnion.
  • Review your financial accounts, insurance statements, and credit reports regularly for unfamiliar activity.
  • Be cautious of unsolicited calls, texts, or emails asking you to verify personal or medical information, since scammers sometimes pose as a breached company or its monitoring service.
  • Keep any documentation related to the incident in case you need it to support a legal claim.

File a Data Breach Lawsuit Against SpineZone

If your personal information was exposed because of this incident at Aesto, LLC, you may have legal options against SpineZone, Aesto, or both. Companies that collect and store sensitive health information, along with the vendors they trust to manage that data, have a responsibility to keep it secure, and when that responsibility is not met, the patients affected deserve accountability.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: On or about December 18, 2025 (incident window December 2-18, 2025)
Date of Breach: not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.