Livara Health Medical Group, the company behind SpineZone clinics and virtual musculoskeletal care, filed a data breach notice with the California attorney general on August 25, disclosing an incident from December 2025.
The filing places the breach between December 2 and December 18, 2025, roughly 266 days before the state notice was submitted. The record lists personal information as exposed and does not state how many people were affected.
Livara runs physician-led spine and musculoskeletal programs that handle patient health records tied to treatment plans, referrals, and insurance claims. Medical data of that kind cannot be cancelled or reissued, leaving affected patients exposed to identity theft, insurance fraud, and prescription fraud long after the incident.
State rules require prompt notification, and the eight-month interval could draw scrutiny from regulators and plaintiffs’ attorneys. Livara is required to notify affected individuals directly, so anyone who has moved since December 2025 should confirm their contact details with the group.