On March 28, 2025, the medical practice ENT and Allergy Associates appeared on the leak site of the Abyss ransomware group in a listing claiming internal files were exfiltrated during a ransomware attack. The clinic, which operates multiple locations across Southeast New York and Northern New Jersey with headquarters in Tarrytown, New York, has not yet disclosed the exact number of patients affected or the full scope of records involved.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch entandallergy.com
Get alerted the next time entandallergy.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about entandallergy.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Available reporting describes a classic ransomware pattern: attackers gained access, exfiltrated data, and later listed the victim on their public leak site when negotiations apparently failed. The exposed material consists of internal files rather than a single structured database. Public reporting indicates the incident was first noted on the Abyss leak page on March 28, 2025. No confirmed total of impacted patient records has been released, leaving many patients uncertain whether their information is among the stolen material.
Why This Matters for You and Your Family
When a medical provider’s systems are breached, the data exposed often includes names, addresses, dates of birth, Social Security numbers, insurance details, and clinical notes. For you or your family members who have visited an ENT and Allergy Associates location, this means sensitive health and financial information may now sit in an attacker’s archive. Medical records are especially damaging because they can be used for insurance fraud, prescription scams, or identity theft that is difficult to unwind. Even if you cannot remember the last time you or a child saw a doctor there, shared family insurance policies or joint addresses can still place your household at risk.
The Doxxing and Identity-Chain Implications
Stolen medical files rarely stay isolated. Attackers routinely cross-reference exposed emails, phone numbers, and addresses against other breach repositories, gaming platforms, and social accounts. A single credential leak from this incident can cascade into account takeovers on email, online banking, or your children’s gaming profiles. Once an attacker maps the connections between your work email, home address, and a child’s Roblox or Fortnite username, the entire household becomes easier to dox or impersonate. Credential leaks like this one therefore create long-term doxxing chains that can surface months or years later.