Texas Spine Consultants Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Texas Spine Consultants
Active investigation Data breach · Healthcare Notices mailed Sep 14, 2026

Received a September 2026 breach notice from Texas Spine Consultants?

Dapeer Law, P.A. is investigating a potential class action against Texas Spine Consultants, PLLC, a Texas spine care practice, on behalf of patients whose medical information and Social Security numbers may have been exposed in the unauthorized access to third-party technology vendor Aesto, LLC disclosed in notice letters filed with the Massachusetts Attorney General on September 14, 2026.

Submit your claim See what to do No fee unless we recover for you
Breach window
December 2 to 18, 2025
Unauthorized access to Aesto cloud infrastructure
Notification delay
About 9 months
Discovered December 2025, letters September 2026
Credit monitoring
Not disclosed
Kroll monitoring, term stated in your letter
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Texas Spine Consultants dated September 2026.
  • Your letter offered complimentary identity monitoring through Kroll, including credit monitoring, fraud consultation, and identity theft restoration, with a membership number and an activation deadline printed in the letter.
  • You had patient information, including medical information or your Social Security number, held by Texas Spine Consultants in the Aesto technology platform.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

Texas Spine Consultants, PLLC disclosed a data security incident in a notice filed with the Massachusetts Attorney General on September 14, 2026. According to the notice, Aesto, LLC, a technology service provider used by the practice, detected a network security incident affecting part of its Amazon Web Services infrastructure. Aesto reports that the unauthorized access occurred between December 2 and December 18, 2025, and that it was discovered on December 18, 2025. Because Texas Spine Consultants patient information was stored within that environment, the incident may have exposed data belonging to the practice's patients.

Aesto engaged outside cybersecurity professionals to investigate and contain the incident, and then conducted a forensic investigation followed by a manual review of the affected documents. That review was completed on May 26, 2026, when Aesto confirmed that patient data belonging to Texas Spine Consultants may have been accessed or acquired. Aesto informed the practice of those findings on June 26, 2026, and Texas Spine Consultants began notifying patients on September 14, 2026. The notice reports that the information involved may have included full name, Social Security number, and medical information related to treatment. The Massachusetts filing lists 24 affected residents of that state, and no nationwide total has been released. The practice states that the investigation found no evidence that any information has been misused, and is offering complimentary Kroll identity monitoring services. Roughly nine months passed between the discovery of the unauthorized access and the mailing of patient letters.

The combination reported here is a serious one. A Social Security number cannot be changed on request and remains usable by identity thieves for years, and medical information carries risks of medical identity theft, fraudulent billing, and insurance fraud that routine credit monitoring does not always detect. Where a health care practice's patient data is exposed through a vendor, our investigation looks at how the practice vetted and monitored that vendor, what contractual and technical safeguards were in place under HIPAA's business associate rules, and whether the roughly nine-month gap between discovery and patient notification complied with state breach notification deadlines.

Massachusetts Attorney General Third-Party Vendor Breach Aesto, LLC Social Security Numbers Medical Information Kroll Identity Monitoring Healthcare Data Breach
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard your Texas Spine Consultants notice letter. The letter contains your Kroll membership number, the activation deadline, and the list of information categories involved in your case, all of which are important evidence if you decide to participate in a lawsuit.

2

Enroll in the free Kroll identity monitoring

Enroll in the Kroll identity monitoring offered in your letter before the activation deadline printed there, using the membership number Texas Spine Consultants provided. Enrollment is available at enroll.krollmonitoring.com, and the response line printed in your letter can answer questions about the membership term. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because a Social Security number may have been involved, also place a free security freeze with Equifax, Experian, and TransUnion, order your free credit reports at AnnualCreditReport.com, and consider requesting an Identity Protection PIN from the IRS to guard against fraudulent tax filings. Because medical information may also have been involved, review the explanation of benefits statements from your health plan for services you did not receive, and request a copy of your medical file if you see anything unfamiliar.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your Texas Spine Consultants notice, explain your options, and advise whether you may be eligible to pursue claims under Texas, Massachusetts, or other state data breach and consumer protection laws.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

December 2 to 18, 2025 Passed
Unauthorized access to the Aesto, LLC cloud environment holding Texas Spine Consultants patient information
December 18, 2025 Passed
Aesto detects the network security incident and engages outside cybersecurity professionals
May 26, 2026 Passed
Manual document review completed, Aesto confirms Texas Spine Consultants patient data may have been accessed or acquired
June 26, 2026 Passed
Aesto informs Texas Spine Consultants of the findings
September 14, 2026 Passed
Notice filed with the Massachusetts Attorney General, letters mailed to patients
See your letter Active
Deadline to activate the complimentary Kroll identity monitoring membership
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, fraudulent accounts or loans opened in your name, fraudulent tax filings, medical identity theft and fraudulent billing, insurance fraud, credit freeze and restoration costs, and the time you spent responding to the incident, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Texas Spine Consultants to implement stronger safeguards over the patient medical information and Social Security numbers it holds, including tighter vendor vetting and contractual security requirements, encryption at rest, data minimization, and prompt notification of affected patients in the event of a future incident.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Texas Spine Consultants. What should I do? +

Keep your Texas Spine Consultants notice letter and the Kroll membership number it contains, activate the complimentary identity monitoring before the deadline printed in your letter, place a free security freeze with Equifax, Experian, and TransUnion, order your free credit reports at AnnualCreditReport.com, review your medical, insurance, and financial statements for unfamiliar activity, consider requesting an Identity Protection PIN from the IRS, document any time or money you spend responding to the incident, and consider speaking with a data breach attorney. If you experience identity theft, report it to the FTC at ftc.gov/idtheft or (877) 438-4338 and file a police report, keeping a copy for your records.

Am I eligible to join a class action against Texas Spine Consultants? +

Patients who received a Texas Spine Consultants notice letter dated September 2026 are the most direct candidates. Eligibility for any legal claim will also depend on your state of residence, the categories of your information that were involved, and any documented losses or out-of-pocket expenses. Because the filing reports that Social Security numbers and medical information may have been involved, recipients may have stronger claims than in incidents limited to contact information. A free case review can help you understand your options.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

According to the notice filed with the Massachusetts Attorney General, the information that may have been involved includes full name, Social Security number, and medical information related to treatment. The public filing does not itemize the exposure patient by patient, and not every recipient's letter will list every category. Your individual letter is the most reliable source for exactly what was involved in your case, so we recommend reviewing it carefully and saving a copy.

Did Texas Spine Consultants offer free credit monitoring? +

Yes. Texas Spine Consultants arranged complimentary identity monitoring through Kroll, which the notice describes as including credit monitoring, fraud consultation, and identity theft restoration services. The term of the membership and the activation deadline are printed in your individual letter rather than in the public filing. Enrollment is at enroll.krollmonitoring.com using the membership number in your letter. Enrolling does not waive your right to pursue legal action.

How many people were affected by the Texas Spine Consultants breach? +

The Massachusetts Attorney General filing reports 24 affected residents of that state. That figure covers Massachusetts only. Texas Spine Consultants has not publicly disclosed how many patients were notified nationwide, and because the incident occurred at a third-party vendor, other Aesto customers may have been affected as well. This page will be updated if additional information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

Texas Spine Consultants filed the breach notice with the Massachusetts Attorney General, and the PDF can be downloaded from the link in the Sources & References section below. If you cannot locate your individual letter, Dapeer Law can help you obtain a copy as part of a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Texas Spine Consultants, PLLC, Kroll, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with Massachusetts Attorney General on September 14, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Alpine Limousine Service Data Breach Lawsuit Investigation

Next
Next

Edenred Pay Data Breach Lawsuit Investigation