
SpineZone, operated under the name Livara Health, has notified patients of a data breach connected to a third party vendor, Aesto Health. Aesto Health is a Birmingham, Alabama-based company that provides data migration and archiving services to healthcare providers nationwide.
Aesto says an unauthorized party accessed a portion of its Amazon Web Services infrastructure between December 2 and December 18, 2025. Aesto ran a forensic investigation and confirmed in May 2026 that protected health information may have been accessed or acquired. This information belonged to patients of the healthcare providers Aesto works with.
SpineZone is one of more than two dozen clients caught up in this breach. Notifications to those clients began going out in late June 2026.
Depending on the individual, exposed information may include full names, dates of birth, Social Security numbers, driver's license or state ID numbers, financial account details, taxpayer identification numbers, and medical or insurance records, including claims and billing history.
If you received a notification letter referencing SpineZone or Aesto Health, start by reading the letter carefully and keep it somewhere safe for your records. Most companies offer free credit monitoring or identity protection after a breach like this, so it's worth signing up. Watch your insurance statements and explanation of benefits notices too. If you spot charges for services you never got, that's a red flag worth following up on right away. It also helps to check your credit reports every so often for accounts or inquiries you don't recognize, and a credit freeze with the major bureaus adds another layer of protection.
Social Security numbers exposed together with medical and insurance information can be used to commit medical identity theft or file fake insurance claims under someone else's name. Cases like this often go unnoticed for a while, and once they surface, they can take a long time to sort out.
Vendor breaches like this one bring up hard questions about who's actually responsible. A healthcare provider and the vendor it hires to manage patient data can both carry some liability, and figuring out where that line falls isn't always simple.
The Lyon Firm represents patients affected by healthcare data breaches nationwide, including cases involving third party vendors, delayed notification, and inadequate security practices.
If your information was involved in the SpineZone or Aesto Health data breach, contact The Lyon Firm today for a free and confidential consultation to discuss your legal options.
Taking the first step doesn’t have to be complicated. In just a few minutes, you can share the basics of your case, and our team will guide you from there: