Were you recently affected by a data breach?

The Asthma Center Data Breach

The Asthma Center (Allergic Disease Associates, P.C.) discovered unauthorized access to its computer systems between October 28 and November 17, 2025. An investigation found that patient names, dates of birth, health insurance details, and medical records may have been exposed. Affected patients were notified in August 2026.

The Asthma Center
Date of Breach: October 28, 2025 - November 17, 2025 (discovered November 2025, notification sent August 2026)
CAU logo

Who was affected:

Clients of The Asthma Center

Impacted Data:

Names, dates of birth, health insurance member numbers, provider names, and medical information including clinical information, diagnosis information, prescription information, and treatment information

The Asthma Center, formally known as Allergic Disease Associates, P.C., has notified patients that an unauthorized actor gained access to its computer systems and may have viewed or downloaded files containing sensitive personal and medical information. Healthcare providers store some of the most sensitive information a person has, from Social Security numbers to detailed treatment histories, and patients trust that this data will be kept secure. When that trust is broken, the people affected deserve clear answers and real options for protecting themselves.

The Asthma Center’s Data Breach Investigation

In November 2025, The Asthma Center learned of suspicious activity affecting its computer systems. The practice moved to confirm the security of its network and opened an investigation to determine what had happened and how many people were affected. That investigation determined that an unauthorized actor had gained access to a limited number of TAC’s systems and, during that window, may have downloaded certain files stored there.

Following the discovery, The Asthma Center conducted a detailed review of the files that were potentially accessed. The purpose of this review was twofold: to identify exactly what categories of information the files contained, and to determine which individuals’ data may have been included. The practice has stated that it is not currently aware of any confirmed cases of identity theft or fraud connected to the incident, but that assurance does not eliminate the risk that exposed data could be misused later, sometimes months or even years after a breach is first discovered.

Healthcare data breaches like this one are becoming increasingly common, and medical practices in particular are frequent targets for cybercriminals. That is because health records typically combine several categories of highly sensitive information in one place, including identifying details, insurance information, and treatment histories, all of which can carry significant value on the black market. Unlike a stolen credit card number, which can be canceled and reissued, information such as a date of birth or a diagnosis history cannot simply be changed, which means the consequences of exposure can follow a person for years.

The combination of data reportedly involved in this incident is also concerning because it goes beyond basic contact information. Names paired with health insurance member numbers, provider names, and details about diagnoses, prescriptions, and treatment can be used to commit medical identity theft, in which a criminal uses a victim’s insurance information to obtain medical care or prescription drugs, or to file fraudulent insurance claims. Victims of medical identity theft often do not discover the fraud until they receive a bill for services they never received or notice unfamiliar claims on an insurance statement, which can take considerably longer to detect than more familiar forms of financial fraud.

Notification timelines for healthcare data breaches are also often longer than for other types of incidents, in part because organizations frequently need extensive forensic review to determine precisely what data was involved before they can notify affected individuals accurately, and in part because many state and federal breach-notification laws set specific windows for that process. The gap between the discovery of unauthorized activity and the eventual notification letter, sometimes several months, is one of the more common criticisms leveled at organizations handling sensitive data, since it can leave affected individuals unaware that they need to start monitoring their accounts and credit reports for warning signs.

Regardless of the ultimate cause, incidents like this one underscore a broader responsibility that healthcare providers and their business associates carry: safeguarding the sensitive personal and medical information entrusted to them by patients. When that information is exposed, whether through a sophisticated cyberattack or a more basic security failure, the people whose data was compromised are the ones left to deal with the fallout, often for years afterward.

Notice letters like the one sent by The Asthma Center are also frequently followed by a wave of phishing attempts, in which scammers pose as the breached company, a credit bureau, or a government agency in an effort to trick recipients into providing additional personal information or payment. Because the letter itself confirms that a person’s information was likely exposed, it can inadvertently make them a more attractive target for follow-up scams, which is why security experts consistently advise verifying any unsolicited communication about a breach directly through the official channels listed in the original notice, rather than clicking links or calling phone numbers provided in a suspicious follow-up message.

When Did This Breach Occur?

According to The Asthma Center’s notice, the unauthorized actor accessed its systems between October 28, 2025, and November 17, 2025. The practice states that it learned of suspicious activity on its network in November 2025 and began an investigation shortly afterward. The Asthma Center began notifying affected individuals in August 2026, several months after the incident was first discovered, giving the practice time to complete its investigation and determine the scope of the information involved.

What Information Was Breached?

The Asthma Center’s investigation determined that the information involved may have included patients’ names in combination with dates of birth, health insurance member numbers, provider names, and medical information, potentially including clinical information, diagnosis information, prescription information, and treatment information. The specific information involved may vary from one individual to another. The practice has not publicly confirmed the total number of people affected by this incident.

What You Can Do

If you received a notification letter from The Asthma Center, there are several steps you can take to help protect yourself, including:

  • Carefully review the letter you received for details specific to your situation.
  • Regularly monitor your health insurance Explanation of Benefits (EOB) statements for any services or claims you do not recognize.
  • Review your financial account statements and credit reports for unfamiliar activity.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus.
  • Be cautious of unsolicited calls, texts, or emails referencing this incident, as scammers sometimes use data breach news to target victims a second time.
  • Contact The Asthma Center’s dedicated assistance line at 1-833-931-9333 with any questions about the incident.

File a Data Breach Lawsuit Against The Asthma Center

If you received a notice that your personal or medical information may have been exposed in The Asthma Center data breach, you may have legal options available to you. Companies and healthcare providers that collect sensitive patient data have a duty to keep that information secure, and when a breach occurs, affected individuals may be entitled to compensation for the risks and burdens they now face.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: August 2026 (reported)
Date of Breach: October 28, 2025 - November 17, 2025 (discovered November 2025, notification sent August 2026)
Date of Breach: Reported to HHS Office for Civil Rights, August 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.