Were you recently affected by a data breach?

Carolina Asthma and Allergy Center Data Breach

Carolina Asthma and Allergy Center, a Charlotte, North Carolina allergy and immunology practice, is reportedly the target of a ransomware attack claimed by the hacker group Chaos, which alleges it accessed 290 GB of patient and administrative data.

Carolina Asthma and Allergy Center
Date of Breach: September 29, 2026 (unconfirmed by the company)
CAU logo

Who was affected:

Clients of Carolina Asthma and Allergy Center

Impacted Data:

According to the claims made by the hacker group Chaos, the data allegedly accessed in this incident may include patient names, dates of birth, medical record numbers, Social Security numbers, phone numbers, and home addresses, along with administrative and financial business records such as procurement and business services documentation. Carolina Asthma and Allergy Center has not yet publicly confirmed which, if any, specific categories of information were actually compromised, and individuals should watch for an official notification letter for details specific to their own records.

Carolina Asthma and Allergy Center, an allergy and immunology healthcare provider with numerous locations throughout the Charlotte, North Carolina area, is reportedly investigating a possible data breach after a ransomware group claimed to have compromised sensitive patient and business data.

Carolina Asthma and Allergy Center’s Data Breach Investigation

Carolina Asthma and Allergy Center (CAAC) operates numerous allergy, asthma, and immunology clinics across the greater Charlotte, North Carolina region, serving thousands of patients across the area. On September 29, 2026, a dark web monitoring listing indicated that a ransomware group calling itself Chaos claimed responsibility for a cyberattack against the practice’s website and network, carolinaasthma.com.

According to the claim, the group stated it had exfiltrated approximately 290 gigabytes of data from the organization’s systems, including files described as “Other Patient Forms” containing names, dates of birth, medical record numbers, Social Security numbers, phone numbers, and addresses, as well as administrative and financial records related to procurement and business services. The group reportedly gave company management a short window to negotiate before threatening to publicly disclose the stolen files.

As of this writing, Carolina Asthma and Allergy Center has not issued a public statement confirming the incident, and no formal breach notification letters have been reported as sent to patients. Reports of the claimed attack have circulated through cybersecurity and dark web monitoring outlets that track ransomware group activity, but the scope, authenticity, and full extent of any data actually taken have not been independently verified by the practice or by regulators.

Attorneys who represent victims of data breaches are aware of the reports involving Carolina Asthma and Allergy Center and are looking into whether the healthcare provider had reasonable data security measures in place to protect the sensitive medical and personal information entrusted to it by patients. Healthcare providers are held to a high standard when it comes to safeguarding protected health information, given the sensitivity of medical records and the potential for identity theft, medical identity fraud, and financial harm when that information falls into the wrong hands.

If Carolina Asthma and Allergy Center confirms that patient data was indeed compromised, those affected may be entitled to pursue compensation through a class action lawsuit. Companies that collect and store sensitive personal and medical information are generally required to implement reasonable administrative, technical, and physical safeguards to prevent unauthorized access. When a data breach occurs, especially one involving a healthcare provider, questions often arise about whether existing cybersecurity protocols were adequate and whether the response to the incident, including the timeliness and content of any notification to those affected, met legal obligations.

Individuals who were patients of Carolina Asthma and Allergy Center, or whose personal information may otherwise have been stored in the practice’s systems, are encouraged to stay alert for official communications from the practice and to monitor their accounts and medical records for any signs of misuse. Class Action U will continue to track developments in this investigation and provide updates as more information becomes available, including whether Carolina Asthma and Allergy Center issues an official notification or confirms the scope of the incident.

When Did This Breach Occur?

The ransomware group Chaos listed its claimed attack against Carolina Asthma and Allergy Center as discovered on September 29, 2026, with an estimated attack date the same day. Carolina Asthma and Allergy Center has not publicly confirmed an exact breach timeline, and no official notification letters describing dates of unauthorized access have been reported as of this writing.

What Information Was Breached?

Based on the hacker group’s own claims, the data allegedly taken may include patient names, dates of birth, medical record numbers, Social Security numbers, phone numbers, and home addresses, in addition to administrative and financial business records. Carolina Asthma and Allergy Center has not yet confirmed which specific data types were compromised, and the full scope will likely only be known once the practice issues an official notification.

What You Can Do

If you are a current or former patient of Carolina Asthma and Allergy Center, consider taking the following steps: monitor your financial accounts and medical statements for unfamiliar activity, request a copy of your credit report and watch for unauthorized inquiries, consider placing a fraud alert or credit freeze with the major credit bureaus, be cautious of phishing emails or calls referencing this incident, and keep any official breach notification letter you may receive as documentation.

You may also wish to speak with a class action attorney to understand your legal options and to determine whether you may be eligible to join a lawsuit seeking compensation for any harm you experienced as a result of this incident. Class Action U can help connect you with attorneys currently investigating this matter.

File a Data Breach Lawsuit Against Carolina Asthma and Allergy Center

If you believe your personal or medical information was compromised as a result of the Carolina Asthma and Allergy Center data breach, you may be entitled to compensation. Data breach lawsuits can help hold companies accountable for failing to adequately protect sensitive information and may result in compensation for those affected, including reimbursement for time spent responding to the breach, out-of-pocket costs, and other damages. To learn more about your legal options and whether you qualify to join a potential class action, Class Action U can connect you with attorneys currently reviewing claims related to this incident.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed
Date of Breach: Not publicly disclosed
Date of Breach: August 28, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.