Aesto
Dec 2025 · Graded Verified · Healthcare and Life Sciences · Government record
AestoDec 2025
disclosed by Livara Health Medical Group - dba SpineZone
SpineZone's patient records were exposed not on its own network but inside Aesto Health, the Birmingham vendor it paid to migrate and archive data into Amazon Web Services. The breach window ran from December 2 to December 18, 2025, and it took Aesto until May 2026 to confirm what protected health information had actually been taken. Names, Social Security numbers, driver's license numbers, financial account details, and full medical and billing histories moved through that one AWS account, along with the records of more than two dozen other providers' patients. SpineZone outsourced the archive; it did not outsource the liability for losing it.
California AG breach notification
Not yet quantified
VVerifiedHealthcare and Life SciencesAbout this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.