Patients of Texas Spine Consultants, PLLC have been notified that a data security incident at a third-party vendor may have exposed some of their protected health information. Healthcare providers and the vendors they rely on to manage patient records have a responsibility to keep that information secure, and a breach at any point in that chain can put patients at risk.
Texas Spine Consultants’s Data Breach Investigation
According to a notification letter, Aesto, LLC, which provides healthcare data migration and archiving services for Texas Spine Consultants, experienced a network security incident that impacted a limited portion of its Amazon Web Services infrastructure on or about December 18, 2025. Aesto stated it worked with external cybersecurity professionals to conduct a thorough investigation, and on May 26, 2026, the company confirmed that between on or about December 2, 2025, and December 18, 2025, a limited amount of protected health information stored on Aesto’s network may have been accessed and/or acquired by an unauthorized actor. Aesto informed Texas Spine Consultants of the incident on June 26, 2026. The company states it has no evidence that any of the information has been misused.
The notification letter describes the information involved in general terms, stating that the files at issue included each recipient’s full name in combination with certain other personal data elements specific to that individual, without a universal list of exactly which data categories were affected for every patient.
Data migration and archiving vendors like Aesto often hold years of accumulated patient records for multiple healthcare providers at once, which makes them an attractive target for cybercriminals seeking to access a large volume of sensitive health information through a single point of entry. When a vendor that supports many different medical practices experiences a breach, the practical effect can be that patients who have never dealt with the vendor directly, and who may not even recognize its name, still have their information exposed.
Protected health information carries particular risks when exposed in a data breach, because it is frequently combined with other identifying details that can be used for medical identity theft, insurance fraud, or targeted phishing schemes designed to look like legitimate follow-up communications from a healthcare provider. Unlike some other categories of stolen data, medical information generally cannot be changed or reissued once compromised, which means the exposure can carry lasting consequences for affected patients.
The gap between when a security incident is first detected and when affected individuals are notified, in this case roughly five months from the December 2025 incident to Aesto’s May 2026 confirmation, is common in healthcare data breach cases, since a forensic review of exactly whose records were involved and what specific information was contained in them can take considerable time to complete thoroughly.
Even though Aesto reports no evidence of misuse to date, affected patients are encouraged to remain vigilant, since stolen health information is sometimes used well after the initial breach, once the initial notification attention has faded.
When Did This Breach Occur?
The security incident occurred on or about December 18, 2025, with unauthorized access potentially occurring between December 2, 2025, and December 18, 2025. Aesto confirmed the incident on May 26, 2026, and notified Texas Spine Consultants on June 26, 2026.
What Information Was Breached?
The information potentially impacted includes each affected patient’s full name in combination with certain other personal data elements specific to that individual. Aesto’s notice did not publicly specify a single universal list of data categories affecting every patient.
What You Can Do
Aesto is offering affected individuals a complimentary membership in Kroll’s identity monitoring services, including Credit Monitoring, Fraud Consultation, and Identity Theft Restoration. If you received a notice regarding this incident, consider taking the following steps:
- Enroll in the complimentary Kroll identity monitoring services referenced in your notification letter.
- Review your financial account statements and credit reports regularly for suspicious activity.
- Consider placing a fraud alert or security freeze on your credit file with Equifax, Experian, and TransUnion.
- Request your free annual credit report at annualcreditreport.com.
- Be cautious of phishing emails or calls referencing this incident or your medical records.
File a Data Breach Lawsuit Against Texas Spine Consultants
If you received a notice that your personal or health information was exposed in this data breach involving Texas Spine Consultants and its vendor Aesto, you may be entitled to compensation. Companies that collect and store sensitive health information have a legal responsibility to protect it, and patients affected by a breach often bear the burden of monitoring their own accounts and protecting themselves from identity theft as a result.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.