SpineZone (Livara Health Medical Group) Data Breach Exposes Patient Names and Protected Health Information

Published: 25 August 2026
Healthcare data breach illustration
Breach Discovery: December 2025Breach Notification: June 2026

SpineZone (Livara Health Medical Group) notified patients that its vendor Aesto suffered a network breach between December 2 and December 18, 2025, exposing patient names and other protected health information stored on Aesto’s systems. Medical history and treatment details were not exposed. Affected patients should enroll in the free 12-month TransUnion credit monitoring offer and watch for phishing attempts.

CompanySpineZone (Livara Health Medical Group)
IndustryHealthcare
Data Types ExposedFull Name, Protected Health Information
People AffectedNot Publicly Disclosed
Attack MethodThird-Party Vendor Breach
Regulators NotifiedNot Publicly Disclosed

What Happened in the SpineZone Data Breach?

SpineZone, operating under Livara Health Medical Group, has notified patients about a data security incident that exposed protected health information. The breach did not happen at SpineZone directly. Instead, it occurred at Aesto, a third-party company that provides healthcare data migration and archiving services for SpineZone.

According to the notification, unauthorized access to Aesto’s network occurred in December 2025. Specifically, Aesto experienced a network security incident that affected a limited portion of its Amazon Web Services infrastructure. The exposure window ran from on or about December 2, 2025, through December 18, 2025, when an unauthorized actor may have accessed or acquired certain files stored on Aesto’s systems.

Once Aesto discovered the intrusion, it began a formal investigation. As a result, the company brought in outside cybersecurity specialists who focus on incidents of this type. This process included an extensive forensic review along with a manual review of affected documents.

That investigation took several months to complete. Aesto did not confirm which patient data had been compromised until May 2026, nearly five months after the incident began. Aesto then informed SpineZone of the breach for the first time in June 2026, prompting SpineZone to notify affected patients directly.

Who was affected?

This breach affects patients whose protected health information was stored within Aesto’s systems on behalf of SpineZone. Because Aesto provides data migration and archiving services, the exposed records likely include patients who received care from SpineZone at some point, regardless of when their visit occurred.

The exact number of affected individuals has not been publicly disclosed. However, the incident involves a healthcare provider’s patient population, meaning the affected group could include people across different age ranges and treatment histories. There is currently no indication in the notification that the exposure was limited to a specific location or patient category.

Because SpineZone relied on a third-party vendor to manage this data, the breach highlights a growing risk in healthcare: patient information does not always stay solely within the walls of the provider that collected it. This means patients may be affected even if they never interacted with Aesto directly.

What Information Was Potentially Exposed?

According to the notification letter, the information potentially involved in this incident includes patients’ full names along with other data elements maintained by Aesto. The notification specifically states that mental or physical condition details, treatment information, and medical history were not part of the exposed data.

  • Full name
  • Protected health information maintained by Aesto

Even without clinical treatment details being exposed, this type of breach still carries real risk. Names tied to a healthcare provider relationship can reveal that someone was a patient at a specific practice. This alone can be used by scammers to craft convincing phishing messages.

In addition, when health-related data appears alongside a patient’s identity, it becomes a more attractive target for fraud schemes. For example, scammers sometimes use partial health information to impersonate insurers or providers when contacting victims. As a result, affected patients should stay alert even though full medical records were not involved.

What is the company doing?

After discovering the incident, Aesto worked with external cybersecurity professionals to investigate the scope of the intrusion. This included a detailed forensic analysis paired with a manual review of the documents that were potentially accessed. SpineZone states that it takes the privacy and security of patient information seriously and continues to evaluate its safeguards.

As part of its response, SpineZone is offering affected individuals a complimentary twelve-month membership in credit monitoring and identity theft protection services through TransUnion. The company has also set up a dedicated toll-free response line so patients can ask questions about the incident. Additionally, SpineZone filed formal notification of this breach with the California Attorney General.

What Should Affected Individuals Do?

Enroll in the Free Credit Monitoring Offer

Affected patients should take advantage of the twelve-month TransUnion credit monitoring and identity theft protection membership being offered at no cost. This service can help detect unusual activity tied to your identity before it becomes a bigger problem.

Because enrollment typically requires action within a set window, it helps to sign up as soon as possible after receiving the notification letter. This service works best when activated early, since it can flag suspicious account activity going forward rather than after damage occurs.

Monitor Your Credit Reports Regularly

Even though this incident did not expose Social Security numbers or financial account details, it remains wise to check your credit reports periodically. You can request a free credit report from each of the three major bureaus once a year through annualcreditreport.com.

Reviewing these reports lets you catch unfamiliar accounts or inquiries early. If you notice anything unusual, you should report it right away to the credit bureau and consider placing a fraud alert on your file.

Watch for Phishing Attempts Referencing SpineZone or Aesto

Because your name may now be linked to a known healthcare provider relationship, scammers could use this detail to make phishing emails or phone calls appear more legitimate. Be cautious of any message claiming to be from SpineZone, Aesto, or a related billing service.

Never click links or share personal details in response to unsolicited messages. Instead, contact SpineZone directly using a verified phone number if you want to confirm whether a message is genuine.

Protect Your Broader Medical Identity

Although this breach did not include treatment details or medical history, it’s still smart to periodically review statements from your healthcare providers and insurer. This helps you spot any services billed that you did not receive.

If you ever notice unfamiliar medical charges or insurance claims, report them to your provider and insurer immediately. Acting quickly can limit the damage and help correct your medical records before problems compound.

Consider Speaking With a Data Breach Attorney

If you received a notification letter about this incident, you may want to speak with an attorney who focuses on data breach cases. They can help you understand whether you qualify for compensation or have grounds for legal action.

Many attorneys offer a free case evaluation, so there is generally little downside to asking questions about your options. This is especially worthwhile if you experience any fraud or identity theft that could be connected to this incident.



Related Data Breaches

Check other recent data breach notifications →