Skip to main content
Jump to a category page

The Asthma Center discovered unauthorized access to its network in November 2025. Public disclosure of the breach didn’t surface until late August 2026, roughly nine to ten months later.

Allergic Disease Associates, P.C., a Philadelphia-area practice operating as The Asthma Center, has disclosed a data breach affecting patient information. The Asthma Center says an unauthorized actor accessed its network between October 28 and November 17, 2025, and that it discovered the intrusion in November 2025. The breach did not become publicly known until late August 2026, when it was listed on a national breach-tracking service.

Source: ID Theft Center Breach Alert listing (08/25/2026); The Asthma Center data-breach coverage.

A Long Gap Between Discovery and Public Disclosure

The roughly nine-to-ten-month gap between when The Asthma Center discovered the intrusion in November 2025 and when the breach became publicly known in late August 2026 is unusually long. The exact date The Asthma Center sent notice letters to individual patients has not been independently confirmed; it is possible notice went out earlier than the public disclosure date, but that has not been verified against a primary source.

What Information Was Exposed?

According to reporting on The Asthma Center’s breach notification, the information involved included:

  • Full name
  • Date of birth
  • Health insurance member number
  • Provider names
  • Medical, clinical, diagnostic, prescription, and treatment information

No Social Security numbers or financial account information have been confirmed as part of this breach.

How Many People Are Affected?

The Asthma Center has not disclosed a total number of affected patients. The practice treats both children and adults across multiple locations in the Philadelphia metropolitan area, Delaware Valley, and South Jersey.

What Is The Asthma Center Offering Affected Individuals?

The Asthma Center has not publicly disclosed whether it is offering credit monitoring or identity protection services. Anyone who received a notice letter should review it directly for enrollment instructions or contact information specific to the offer made to them.

Your Information Is at Risk

Health insurance member numbers, provider names, and detailed clinical, diagnostic, prescription, and treatment information can be used to commit medical identity theft, including someone using your insurance information to obtain treatment or prescriptions in your name, or to file fraudulent insurance claims. Affected individuals should review their health insurance statements, known as explanation-of-benefits notices, for any services or prescriptions they don’t recognize.

Do You Have Legal Options?

Medical practices that collect and store health insurance information and clinical, diagnostic, and treatment records have a legal duty to secure that data and to notify affected individuals without unreasonable delay.

Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you received a notice letter from The Asthma Center.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.

FAQ

Who is affected by The Asthma Center data breach?

The Asthma Center has not disclosed a total number of affected patients. The practice treats both children and adults across the Philadelphia metropolitan area, Delaware Valley, and South Jersey.

What information was exposed?

Full name, date of birth, health insurance member number, provider names, and medical, clinical, diagnostic, prescription, and treatment information. No Social Security numbers or financial account information have been confirmed as involved.

When did the breach happen, and why did it take so long to find out?

The Asthma Center says unauthorized access occurred between October 28 and November 17, 2025, and that it discovered the intrusion in November 2025. The breach did not become publicly known until late August 2026, roughly nine to ten months later. The Asthma Center has not publicly explained the reason for that gap.

Is The Asthma Center offering credit monitoring?

That has not been publicly disclosed. If you received a notice letter, check it directly for enrollment instructions or contact information.

My child is a patient at The Asthma Center. Does this affect them too?

The practice treats both children and adults, and the breach notification does not appear to be limited by age. If your child is a patient, review any notice letter you received carefully, since a minor’s health insurance and medical information can be misused just as an adult’s can, sometimes without being noticed for a long time.

Do I have a legal claim?

Medical practices that collect and store health insurance and clinical information have a legal duty to secure that data and to notify affected patients without unreasonable delay. If you received a notice letter from The Asthma Center, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now