Texas Spine Consultants Data Breach Lawsuit Investigation
Received a September 2026 breach notice from Texas Spine Consultants?
Dapeer Law, P.A. is investigating a potential class action against Texas Spine Consultants, PLLC, a Texas spine care practice, on behalf of patients whose medical information and Social Security numbers may have been exposed in the unauthorized access to third-party technology vendor Aesto, LLC disclosed in notice letters filed with the Massachusetts Attorney General on September 14, 2026.
Who may qualify
You may be eligible to participate in a class action if any of the following applies:
- You received a data breach notification letter from Texas Spine Consultants dated September 2026.
- Your letter offered complimentary identity monitoring through Kroll, including credit monitoring, fraud consultation, and identity theft restoration, with a membership number and an activation deadline printed in the letter.
- You had patient information, including medical information or your Social Security number, held by Texas Spine Consultants in the Aesto technology platform.
- No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
- Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.
Not sure if you qualify?
Send us your notice, we'll confirm your eligibility at no cost.
What happened
Texas Spine Consultants, PLLC disclosed a data security incident in a notice filed with the Massachusetts Attorney General on September 14, 2026. According to the notice, Aesto, LLC, a technology service provider used by the practice, detected a network security incident affecting part of its Amazon Web Services infrastructure. Aesto reports that the unauthorized access occurred between December 2 and December 18, 2025, and that it was discovered on December 18, 2025. Because Texas Spine Consultants patient information was stored within that environment, the incident may have exposed data belonging to the practice's patients.
Aesto engaged outside cybersecurity professionals to investigate and contain the incident, and then conducted a forensic investigation followed by a manual review of the affected documents. That review was completed on May 26, 2026, when Aesto confirmed that patient data belonging to Texas Spine Consultants may have been accessed or acquired. Aesto informed the practice of those findings on June 26, 2026, and Texas Spine Consultants began notifying patients on September 14, 2026. The notice reports that the information involved may have included full name, Social Security number, and medical information related to treatment. The Massachusetts filing lists 24 affected residents of that state, and no nationwide total has been released. The practice states that the investigation found no evidence that any information has been misused, and is offering complimentary Kroll identity monitoring services. Roughly nine months passed between the discovery of the unauthorized access and the mailing of patient letters.
The combination reported here is a serious one. A Social Security number cannot be changed on request and remains usable by identity thieves for years, and medical information carries risks of medical identity theft, fraudulent billing, and insurance fraud that routine credit monitoring does not always detect. Where a health care practice's patient data is exposed through a vendor, our investigation looks at how the practice vetted and monitored that vendor, what contractual and technical safeguards were in place under HIPAA's business associate rules, and whether the roughly nine-month gap between discovery and patient notification complied with state breach notification deadlines.
What to do if you received a letter
Keep your notice letter
Do not discard your Texas Spine Consultants notice letter. The letter contains your Kroll membership number, the activation deadline, and the list of information categories involved in your case, all of which are important evidence if you decide to participate in a lawsuit.
Enroll in the free Kroll identity monitoring
Enroll in the Kroll identity monitoring offered in your letter before the activation deadline printed there, using the membership number Texas Spine Consultants provided. Enrollment is available at enroll.krollmonitoring.com, and the response line printed in your letter can answer questions about the membership term. Accepting this benefit does not waive your right to pursue legal action.
Place a fraud alert or credit freeze
Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because a Social Security number may have been involved, also place a free security freeze with Equifax, Experian, and TransUnion, order your free credit reports at AnnualCreditReport.com, and consider requesting an Identity Protection PIN from the IRS to guard against fraudulent tax filings. Because medical information may also have been involved, review the explanation of benefits statements from your health plan for services you did not receive, and request a copy of your medical file if you see anything unfamiliar.
Speak with a data breach attorney
Consultations with Dapeer Law are free and confidential. We'll review your Texas Spine Consultants notice, explain your options, and advise whether you may be eligible to pursue claims under Texas, Massachusetts, or other state data breach and consumer protection laws.
Submit your notice for a free review
Two minutes online. A licensed attorney reviews every submission.
Breach timeline
Compensation you may be entitled to
Out-of-pocket expenses
Credit freezes, identity restoration services, and other costs incurred responding to the breach.
Time spent monitoring
Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.
Identity theft & fraud losses
Unreimbursed funds stolen from accounts, unauthorized credit lines, fraudulent accounts or loans opened in your name, fraudulent tax filings, medical identity theft and fraudulent billing, insurance fraud, credit freeze and restoration costs, and the time you spent responding to the incident, or tax refund fraud tied to the breach.
Statutory damages
Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.
Injunctive relief
Court orders requiring Texas Spine Consultants to implement stronger safeguards over the patient medical information and Social Security numbers it holds, including tighter vendor vetting and contractual security requirements, encryption at rest, data minimization, and prompt notification of affected patients in the event of a future incident.
Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.
Common questions
I received a data breach letter from Texas Spine Consultants. What should I do? +
Keep your Texas Spine Consultants notice letter and the Kroll membership number it contains, activate the complimentary identity monitoring before the deadline printed in your letter, place a free security freeze with Equifax, Experian, and TransUnion, order your free credit reports at AnnualCreditReport.com, review your medical, insurance, and financial statements for unfamiliar activity, consider requesting an Identity Protection PIN from the IRS, document any time or money you spend responding to the incident, and consider speaking with a data breach attorney. If you experience identity theft, report it to the FTC at ftc.gov/idtheft or (877) 438-4338 and file a police report, keeping a copy for your records.
Am I eligible to join a class action against Texas Spine Consultants? +
Patients who received a Texas Spine Consultants notice letter dated September 2026 are the most direct candidates. Eligibility for any legal claim will also depend on your state of residence, the categories of your information that were involved, and any documented losses or out-of-pocket expenses. Because the filing reports that Social Security numbers and medical information may have been involved, recipients may have stronger claims than in incidents limited to contact information. A free case review can help you understand your options.
How much money could I receive from a class action lawsuit? +
Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.
What personal information was exposed in the breach? +
According to the notice filed with the Massachusetts Attorney General, the information that may have been involved includes full name, Social Security number, and medical information related to treatment. The public filing does not itemize the exposure patient by patient, and not every recipient's letter will list every category. Your individual letter is the most reliable source for exactly what was involved in your case, so we recommend reviewing it carefully and saving a copy.
Did Texas Spine Consultants offer free credit monitoring? +
Yes. Texas Spine Consultants arranged complimentary identity monitoring through Kroll, which the notice describes as including credit monitoring, fraud consultation, and identity theft restoration services. The term of the membership and the activation deadline are printed in your individual letter rather than in the public filing. Enrollment is at enroll.krollmonitoring.com using the membership number in your letter. Enrolling does not waive your right to pursue legal action.
How many people were affected by the Texas Spine Consultants breach? +
The Massachusetts Attorney General filing reports 24 affected residents of that state. That figure covers Massachusetts only. Texas Spine Consultants has not publicly disclosed how many patients were notified nationwide, and because the incident occurred at a third-party vendor, other Aesto customers may have been affected as well. This page will be updated if additional information becomes available.
Is there a deadline to take legal action? +
Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.
How do I get a copy of the official breach notice? +
Texas Spine Consultants filed the breach notice with the Massachusetts Attorney General, and the PDF can be downloaded from the link in the Sources & References section below. If you cannot locate your individual letter, Dapeer Law can help you obtain a copy as part of a free consultation.
Sources & references
- Official breach notice filing · Massachusetts Attorney General, Texas Spine Consultants, PLLC Security Breach Notice (PDF)
- Identity monitoring enrollment · Kroll, enroll.krollmonitoring.com
- Credit bureau freezes · Equifax · Experian · TransUnion
- Free weekly credit reports · AnnualCreditReport.com
- Identity theft recovery guide · FTC IdentityTheft.gov
Don't let the deadline decide for you. Submit your claim today.
You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.