Were you recently affected by a data breach?

Texas Spine Consultants Data Breach

Aesto, a healthcare data migration and archiving vendor for Texas Spine Consultants, notified patients that a network security incident may have exposed some of their protected health information. The company is offering identity monitoring to those affected.

Texas Spine Consultants
Date of Breach: Not publicly disclosed
CAU logo

Who was affected:

Clients of Texas Spine Consultants

Impacted Data:

Names and certain other personal data elements specific to each individual

Patients of Texas Spine Consultants, PLLC have been notified that a data security incident at a third-party vendor may have exposed some of their protected health information. Healthcare providers and the vendors they rely on to manage patient records have a responsibility to keep that information secure, and a breach at any point in that chain can put patients at risk.

Texas Spine Consultants’s Data Breach Investigation

According to a notification letter, Aesto, LLC, which provides healthcare data migration and archiving services for Texas Spine Consultants, experienced a network security incident that impacted a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Aesto stated it worked with external cybersecurity professionals to conduct a thorough investigation, and on May 26, 2026, the company confirmed that between on or about December 2, 2025, and December 18, 2025, a limited amount of protected health information stored on Aesto’s network may have been accessed and/or acquired by an unauthorized actor. Aesto informed Texas Spine Consultants of the incident on June 26, 2026. The company states it has no evidence that any of the information has been misused.

The notification letter describes the information involved in general terms, stating that the files at issue included each recipient’s full name in combination with certain other personal data elements specific to that individual, without a universal list of exactly which data categories were affected for every patient.

Data migration and archiving vendors like Aesto often hold years of accumulated patient records for multiple healthcare providers at once, which makes them an attractive target for cybercriminals seeking to access a large volume of sensitive health information through a single point of entry. When a vendor that supports many different medical practices experiences a breach, the practical effect can be that patients who have never dealt with the vendor directly, and who may not even recognize its name, still have their information exposed.

Protected health information carries particular risks when exposed in a data breach, because it is frequently combined with other identifying details that can be used for medical identity theft, insurance fraud, or targeted phishing schemes designed to look like legitimate follow-up communications from a healthcare provider. Unlike some other categories of stolen data, medical information generally cannot be changed or reissued once compromised, which means the exposure can carry lasting consequences for affected patients.

The gap between when a security incident is first detected and when affected individuals are notified, in this case roughly five months from the December 2025 incident to Aesto’s May 2026 confirmation, is common in healthcare data breach cases, since a forensic review of exactly whose records were involved and what specific information was contained in them can take considerable time to complete thoroughly.

Even though Aesto reports no evidence of misuse to date, affected patients are encouraged to remain vigilant, since stolen health information is sometimes used well after the initial breach, once the initial notification attention has faded.

When Did This Breach Occur?

The security incident occurred on or about December 18, 2025, with unauthorized access potentially occurring between December 2, 2025, and December 18, 2025. Aesto confirmed the incident on May 26, 2026, and notified Texas Spine Consultants on June 26, 2026.

What Information Was Breached?

The information potentially impacted includes each affected patient’s full name in combination with certain other personal data elements specific to that individual. Aesto’s notice did not publicly specify a single universal list of data categories affecting every patient.

What You Can Do

Aesto is offering affected individuals a complimentary membership in Kroll’s identity monitoring services, including Credit Monitoring, Fraud Consultation, and Identity Theft Restoration. If you received a notice regarding this incident, consider taking the following steps:

  • Enroll in the complimentary Kroll identity monitoring services referenced in your notification letter.
  • Review your financial account statements and credit reports regularly for suspicious activity.
  • Consider placing a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion.
  • Request your free annual credit report at annualcreditreport.com.
  • Be cautious of phishing emails or calls referencing this incident or your medical records.

File a Data Breach Lawsuit Against Texas Spine Consultants

If you received a notice that your personal or health information was exposed in this data breach involving Texas Spine Consultants and its vendor Aesto, you may be entitled to compensation. Companies that collect and store sensitive health information have a legal responsibility to protect it, and patients affected by a breach often bear the burden of monitoring their own accounts and protecting themselves from identity theft as a result.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: June 3, 2026
Date of Breach: Notification dated August 6, 2026; incident date not publicly disclosed
Date of Breach: Not publicly disclosed; review completed August 28, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.