Carolina Asthma Data Breach Exposes Social Security Numbers and Patient Records

Published: 29 September 2026
Healthcare data breach illustration
Breach Discovery: September 2026Breach Notification: Not Publicly Disclosed

A ransomware group known as Chaos claims to have stolen 290 GB of data from Carolina Asthma, a US healthcare provider, in September 2026, allegedly including patient names, Social Security numbers, medical record numbers, and financial records. Carolina Asthma has not publicly confirmed the incident. Affected individuals should monitor credit reports and consider a credit freeze immediately.

CompanyCarolina Asthma
IndustryHealthcare
Data Types ExposedFull Names, Dates of Birth, Medical Record Numbers, Social Security Numbers, Phone Numbers, Home Addresses, Financial and Administrative Records
People AffectedNot Publicly Disclosed
Attack MethodRansomware
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Carolina Asthma Data Breach?

A ransomware group calling itself Chaos claims it broke into the network of Carolina Asthma, a healthcare provider based in the United States. According to the group’s own claims, it stole roughly 290 GB of internal data. This alleged Carolina Asthma data breach reportedly includes patient forms, administrative files, and financial records.

Based on the group’s public statements, unauthorized access to the network occurred in September 2026. The attackers say they gave company leadership a short window to respond before threatening to publish the stolen files. As of now, Carolina Asthma has not publicly confirmed the incident or the attacker’s claims.

Because this report stems from a ransomware group’s leak-site listing, many details remain unverified. There is no independent confirmation yet of how the intrusion happened, how long attackers were inside the network, or whether forensic investigators have been brought in. As a result, affected patients should treat these claims seriously while watching for official updates.

Ransomware groups frequently use these public deadlines as pressure tactics to force a ransom payment. This means the 290 GB figure and the described contents have not been verified by any neutral third party. Still, the specificity of the claimed data categories raises real concern for anyone connected to this provider.

Who was affected?

The individuals affected by this alleged Carolina Asthma data breach likely include current and former patients. Given the nature of the stolen files, administrative staff and possibly vendors involved in procurement or business services could also be implicated. However, Carolina Asthma has not released an official list of affected groups.

The exact number of people affected has not been publicly disclosed. Because healthcare providers typically store years of patient records, the true scope could be substantial. In addition, since asthma treatment often involves ongoing care, both adult and pediatric patients may be part of the exposed population.

At this stage, there’s no confirmed information about the geographic reach of the incident. Most patients are likely located in the provider’s regional service area. Nonetheless, anyone who has received care from this practice should stay alert for updates.

What Information Was Potentially Exposed?

According to the threat actor’s claims, the stolen data includes detailed patient forms along with administrative and financial records. This is particularly troubling because these documents often combine identity data with sensitive health details in a single file.

  • Full names
  • Dates of birth
  • Medical record numbers (MRN)
  • Social Security numbers
  • Phone numbers
  • Home addresses
  • Administrative and financial business records
  • Procurement and business services documentation

If these claims are accurate, the combination of Social Security numbers with names and birth dates creates a serious identity theft risk. Criminals can use this type of data to open new credit accounts, file fraudulent tax returns, or apply for loans in a victim’s name. Because medical record numbers are also allegedly included, patients could additionally face medical identity theft, where someone uses a person’s identity to obtain treatment or prescriptions.

Beyond financial fraud, exposed patient forms could reveal health conditions or treatment history. This kind of exposure can lead to unwanted disclosure of private medical information. Furthermore, because the data reportedly spans administrative and financial functions, employees or contract partners could also face fraud risks tied to business records.

What is the company doing?

Because this incident stems from a ransomware group’s own claims, there’s no confirmed public statement yet from Carolina Asthma describing an investigation or response. The organization has not publicly confirmed the breach, and it has not described any remediation, notification, or credit monitoring steps at this time.

As this situation develops, affected individuals should watch for official communication directly from Carolina Asthma. If the incident is confirmed, healthcare providers are generally required to notify affected patients under federal law. Until that happens, it’s important not to assume any specific response has taken place.

What Should Affected Individuals Do?

Monitor Your Credit Reports

Because Social Security numbers are allegedly part of the stolen data, it’s wise to check your credit reports regularly. You can request free reports from all three major credit bureaus through AnnualCreditReport.com. Reviewing them closely can help you spot new accounts or inquiries you didn’t authorize.

In addition, consider spacing out your requests so you can check your credit throughout the year instead of all at once. This gives you an ongoing view of your financial activity. If you notice anything suspicious, report it to the credit bureau immediately and consider speaking with a data breach attorney about your options.

Consider a Fraud Alert or Credit Freeze

Given the alleged exposure of Social Security numbers, placing a fraud alert or credit freeze can add a strong layer of protection. A fraud alert requires lenders to verify your identity before extending new credit. A credit freeze goes further by blocking access to your credit file entirely.

Both options are free and can be requested directly through each credit bureau. Because identity thieves often act quickly after a breach, taking this step sooner rather than later is the safest approach. You can lift a freeze temporarily whenever you need to apply for new credit yourself.

Protect Against Medical Identity Theft

Because medical record numbers and patient forms were reportedly involved, it’s important to review any medical bills or insurance statements carefully. Look for unfamiliar treatments, prescriptions, or provider visits you don’t recognize. This could indicate someone is using your identity to receive care.

If you spot anything unusual, contact your insurance provider and the healthcare facility right away. You should also request a copy of your medical records to check for inaccuracies. Correcting fraudulent entries early can prevent complications with your future care or coverage.

Stay Alert for Phishing Attempts

Because personal details like names, addresses, and phone numbers were allegedly exposed, scammers may use this information to craft convincing phishing messages. These could arrive by email, text, or phone call, often pretending to be from a legitimate healthcare provider or financial institution.

As a precaution, never click links or share personal details in response to unsolicited messages. Instead, contact the organization directly using a verified phone number or website. This simple habit can prevent attackers from tricking you into handing over even more sensitive information.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

Browse all recent data breaches →