[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWCu6KwzQgYHdyuVI4Df1zBVB3oVlaEAAht5NL6Uayjg":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":22,"source":23,"isVerified":4,"isSpamList":24,"isSensitive":4,"processingStatus":25,"logoUrl":26,"contentUpdatedAt":16,"hasEnglishDescription":4,"severity":27},"6a675019210a72e3a19ed834","AllerVieHealth2025","AllerVie Health 2025 Data Breach","allervie-health-2025","allervie.com",{"name":12,"sector":13,"country":14,"website":10},"AllerVie Health","Healthcare","United States","2025-10-24T00:00:00.000Z","2026-07-27T12:33:29.052Z",80521,[19,20,21],"Names","Social Security numbers","Driver’s license or state identification numbers","\u003Cp>\u003Cstrong>The AllerVie Health 2025 data breach\u003C\u002Fstrong> involved the allergy and immunology provider detecting unusual network activity November 2, 2025 and determining that a limited amount of information was subject to unauthorized access between October 24 and November 3. The notification also covers people who provided information to certain Ohio clinics.\u003C\u002Fp>\n\u003Cp>The official HHS Office for Civil Rights breach portal reports 80,521 affected people and classifies the event as a network-server hacking\u002FIT incident. pwnCount and totalRecords carry that public population. importedRecordCount is zero because no person-level file or account was transferred into LeakData.\u003C\u002Fp>\n\u003Ch2>How Was the AllerVie Health Breach Confirmed?\u003C\u002Fh2>\n\u003Cp>The primary source is AllerVie Health's consumer letter dated December 22, 2025. It confirms the November 2 discovery, October 24–November 3 access window, November 24 data-review result, password resets and law-enforcement notification, 24 months of Cyberscout services, and the assistance line at 833-877-1419.\u003C\u002Fp>\n\u003Cp>The second source is the official HHS\u002FOCR row dated December 23, 2025 for 80,521 people. Massachusetts and New Hampshire attorney-general records independently support the consumer notice and involvement of names, Social Security numbers, and driver's license or state identification numbers. A secondary actor name is excluded because the provider notice does not confirm it.\u003C\u002Fp>\n\u003Ch2>What Happened Between October 24 and November 3, 2025?\u003C\u002Fh2>\n\u003Cp>AllerVie discovered unusual activity in its network November 2 and immediately opened an investigation. The review determined that a limited amount of information was subject to unauthorized access from October 24 through November 3. The provider examined the content to identify information types and associated people and finished that work November 24.\u003C\u002Fp>\n\u003Cp>The public letter does not explain the initial-entry method, account or vulnerability used, whether information was definitively removed, or who the actor was. This entry therefore relies on the confirmed unauthorized network access and does not present ransomware or actor claims from a secondary page as the provider's official finding.\u003C\u002Fp>\n\u003Ch2>What Identity Information Was Involved?\u003C\u002Fh2>\n\u003Cp>State filings identify fields that varied by person as names, Social Security numbers, and driver's license or state identification numbers. The recipient-specific data field is redacted in the public sample letter. This entry uses only data classes disclosed through regulatory filings.\u003C\u002Fp>\n\u003Cp>A name combined with an SSN and government identification number can increase impersonation, new-account, and persuasive-phishing risk. A notice recipient can consider monitoring credit reports, placing a fraud alert or credit freeze, and reviewing address or new-account changes. The record does not assume every person had every field involved.\u003C\u002Fp>\n\u003Ch2>How Should the Healthcare Context Be Assessed?\u003C\u002Fh2>\n\u003Cp>The incident concerned a healthcare-provider network and was reported to HHS as involving protected health information, but the public sample letter does not identify specific health subtypes such as diagnoses, treatments, medications, insurance fields, or medical record numbers. Those data classes are therefore not added without evidence.\u003C\u002Fp>\n\u003Cp>Someone aware of an AllerVie clinic relationship could craft a fake appointment, result, invoice, or treatment message. Notice recipients should verify unexpected healthcare communications using a known clinic telephone number or patient portal. A message is not legitimate merely because it includes a real clinic or person name.\u003C\u002Fp>\n\u003Ch2>How Should the 80,521 Figure Be Interpreted?\u003C\u002Fh2>\n\u003Cp>The 80,521 figure is the affected population reported to HHS\u002FOCR and is used as the current official nationwide total. It is not a volume of accessed files or a number of users, rows, or accounts loaded into LeakData. pwnCount and totalRecords are 80,521, while importedRecordCount is zero to reflect that no raw person-level data is held.\u003C\u002Fp>\n\u003Cp>Resident figures disclosed in Massachusetts, New Hampshire, Rhode Island, or other states are subsets of this nationwide population and are not added again. The Springdale, Kenwood, West Chester, Clifton, and Anderson clinics named in the letter are within the same AllerVie event and are not split into duplicate breach entries.\u003C\u002Fp>\n\u003Ch2>How Did AllerVie Respond and What Should Recipients Do?\u003C\u002Fh2>\n\u003Cp>AllerVie said it reset passwords, notified law enforcement, conducted a thorough investigation, and reviewed data-protection policies and procedures. It arranged 24 months of complimentary credit monitoring and identity protection through Cyberscout; the sample letter gives recipients 90 days from the letter date to enroll.\u003C\u002Fp>\n\u003Cp>A recipient should rely on the fields in their own letter and consider a credit freeze, fraud alert, and new-account monitoring if an SSN or government ID was involved. The official 833-877-1419 line is listed for weekdays from 8:00 a.m. to 8:00 p.m. Eastern. Do not share a password, full SSN, payment, or one-time code in an unexpected message.\u003C\u002Fp>","AllerVie Health consumer notice, HHS\u002FOCR report, and Massachusetts Attorney General filing",false,"completed","\u002Fuploads\u002Flogo\u002Fallervie_com.png","Medium"]