Were you recently affected by a data breach?

Carolina Internal Medicine Data Breach

Carolina Internal Medicine, an internal medicine practice in Asheville and Clyde, North Carolina, has notified Vermont regulators that a data breach exposed the Social Security numbers of nine patients. Affected individuals should act now to protect their identity.

Carolina Internal Medicine
Date of Breach: Reported to the Vermont Attorney General's Office on August 21, 2026; underlying breach and discovery dates not yet publicly disclosed.
CAU logo

Who was affected:

Clients of Carolina Internal Medicine

Impacted Data:

Social Security numbers

Carolina Internal Medicine, an independent physician-owned internal medicine practice serving patients in Asheville and Clyde, North Carolina, has confirmed a data security incident affecting a subset of its patients. Healthcare providers that maintain protected health information and Social Security numbers carry a heightened responsibility to safeguard that data from unauthorized access, and any lapse in that responsibility can expose patients to a lasting risk of identity theft and fraud.

Carolina Internal Medicine’s Data Breach Investigation

On August 21, 2026, Carolina Internal Medicine notified the Vermont Attorney General’s Office of a data security incident involving the personal information of its patients. According to the notice filed with Vermont regulators, the incident affected nine Vermont residents whose Social Security numbers were involved. Carolina Internal Medicine, which has provided adult primary care and internal medicine services to patients in Western North Carolina since 1970, is a physician-owned practice operating locations in Asheville and Clyde. As of this notice, the practice has not publicly disclosed the specific cause of the incident, the exact dates the breach occurred or was discovered, or whether patients outside Vermont were also affected, though multi-state notification requirements often mean a healthcare provider files similar notices with several state regulators for the same underlying incident.

Healthcare providers, including small and mid-sized practices like Carolina Internal Medicine, have become frequent targets for cyberattacks and inadvertent data exposures because the records they maintain are unusually valuable to criminals. A single patient file can combine a Social Security number with medical history, insurance information, and other identifying details, making healthcare data significantly more useful for identity theft than a stolen credit card number alone, since a compromised card can simply be canceled while a Social Security number cannot. Independent physician practices are often especially attractive targets because they may have smaller dedicated cybersecurity budgets and staff than large hospital systems, even though they are held to the same regulatory standards under HIPAA and applicable state data breach notification laws. Attackers increasingly recognize that mid-sized medical offices sit at an intersection of valuable data and comparatively lean security resources.

When a Social Security number is exposed in a data breach, the risk to affected individuals extends well beyond the immediate incident. A Social Security number is a persistent identifier that cannot be changed the way a password or account number can, so once it is compromised, it can be used indefinitely by bad actors to open new lines of credit, file fraudulent tax returns, apply for government benefits, or create synthetic identities that blend a real Social Security number with fabricated personal details. Victims of Social Security number theft frequently do not discover the misuse for months or years after the underlying breach, which is one reason regulators require companies to notify affected individuals promptly and why credit monitoring and identity theft protection services are commonly offered in the wake of an incident like this one.

State data breach notification laws, including Vermont’s Security Breach Notice Act, generally require organizations to notify affected residents and the state Attorney General’s Office within a defined window once a breach involving personal information is discovered, though the exact timeline and triggering thresholds vary from state to state. A notification filed with a single state’s Attorney General, as Carolina Internal Medicine did with Vermont, does not necessarily mean the incident was limited to that state’s residents. It is common for a healthcare provider to separately notify residents of every state where affected patients live, and additional details about the scope of the breach, including whether other data types beyond Social Security numbers were involved, sometimes emerge only after separate state filings or direct notification letters are issued.

Individuals notified of a data breach involving their Social Security number should also be alert to a secondary risk beyond direct financial fraud: follow-up phishing attempts. Scammers frequently monitor public breach notifications and news coverage, then impersonate the breached company, a credit bureau, or a government agency in emails, text messages, or phone calls designed to trick recipients into providing additional personal information or login credentials under the pretense of resolving the breach. Patients of Carolina Internal Medicine who receive a breach notification letter should independently verify its authenticity by contacting the practice directly through a phone number obtained from its official website, rather than any number or link provided in an unsolicited message, before providing any additional information.

When Did This Breach Occur?

Carolina Internal Medicine notified the Vermont Attorney General’s Office of this data security incident on August 21, 2026. The notice identifies nine Vermont residents as affected and lists Social Security numbers as the category of information involved, but as of this notice, the practice has not publicly disclosed the specific date the underlying incident occurred, the date it was discovered internally, or the date affected individuals were formally notified by mail. These dates, when a breach occurs, when it is discovered, and when notice is finally sent, are often different from one another and can span weeks or months. Companies are generally required to complete a forensic investigation to determine the scope of a breach before notifying affected individuals and regulators, which can delay the notification date well past the actual date of compromise. If Carolina Internal Medicine discloses additional information about these dates, or if the underlying incident affected residents in other states through separate filings, that information will be reflected here as it becomes available.

What Information Was Breached?

According to the notice filed with the Vermont Attorney General’s Office, the information involved in this incident included Social Security numbers belonging to affected patients. Carolina Internal Medicine has not publicly disclosed whether additional categories of information, such as names, dates of birth, medical record numbers, insurance information, or other protected health information, were also involved, though a healthcare provider’s records commonly include these data types alongside Social Security numbers. Patients affected by this incident should not assume the exposure was limited to a Social Security number alone simply because that is the only category specifically identified in the current public notice; it is common for additional details about the scope of a breach to emerge only in the direct notification letters mailed to affected individuals. Anyone who received or later receives a letter from Carolina Internal Medicine about this incident should read it carefully to confirm exactly which of their personal information was involved.

What You Can Do

Patients affected by the Carolina Internal Medicine data breach can take several steps to help protect themselves:

  • Review the breach notification letter carefully, if one is received, to confirm what personal information was involved and whether free credit monitoring or identity theft protection services are being offered.
  • Place a fraud alert or a security freeze on credit files with the three major credit bureaus, Equifax, Experian, and TransUnion, to make it harder for anyone to open new accounts using a stolen Social Security number.
  • Monitor bank and credit card statements, as well as credit reports, regularly for unfamiliar activity, and consider requesting a free annual credit report from each bureau.
  • Be cautious of unsolicited emails, texts, or phone calls referencing the breach, and never provide personal information or click links in messages claiming to resolve the incident without independently verifying the sender.
  • File a report with the Federal Trade Commission at IdentityTheft.gov if signs of identity theft or fraud appear following the breach.

Taking these steps promptly can reduce the risk that a stolen Social Security number is used to open fraudulent accounts or file false tax returns in an affected patient’s name.

File a Data Breach Lawsuit Against Carolina Internal Medicine

Patients whose Social Security numbers were exposed in the Carolina Internal Medicine data breach may have legal options available to them. Companies and healthcare providers that collect and store sensitive personal information have a legal responsibility to implement reasonable safeguards to protect that data, and when a breach occurs, affected individuals can sometimes pursue compensation for the time, expense, and ongoing risk created by the exposure of their information. An experienced data breach attorney can help evaluate whether Carolina Internal Medicine’s data security practices met applicable legal standards and what recovery options may be available to those impacted.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: December 18, 2025 (discovered by vendor Aesto, LLC)
Date of Breach: June 22, 2026 (discovered)
Date of Breach: Reported to the Vermont Attorney General's Office on August 21, 2026; underlying breach and discovery dates not yet publicly disclosed.
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.