ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

All About Women’s Care alerts patients after data security incident

Colorado-based All About Women’s Care said a data security incident it suffered earlier this year compromised the sensitive personal information of more than 10,000 individuals.

Linked InXFacebook
bookmark_borderSave to Library

All About Women’s Care has disclosed that a data security incident earlier this year affected the sensitive personal information of more than 10,000 individuals.

 

All About Women’s Care is a Colorado-based OB-GYN practice that provides comprehensive women’s healthcare services, including obstetric and gynecological care, prenatal care, infertility treatment, menopause management, and preventive health services.

 

In a data security incident notice published on its website, AAWC said that on April 9, t became aware of unauthorised activity linked to an employee VPN account. The healthcare provider immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected systems and notified relevant law enforcement authorities about the incident.

 

“The investigation determined that an unauthorised actor gained access to AAWC’s network environment and accessed or acquired certain files. The unauthorised actor also provided a sample of files as part of an extortion communication,” AAWC said.

 

The compromised data includes names, dates of birth, Social Security numbers, driver’s license numbers, other identification numbers, clinical information, lab results, prescription information, provider information, health insurance information, medical documents, ultrasound images, and copies of passports or identification documents.

 

In a filing with the U.S. Department of Health and Human Services’ Office for Civil Rights, AAWC said it has identified 12,000 individuals impacted by the incident.

 

While the healthcare provider said it found no evidence that the compromised information had been misused, it urged affected individuals to closely monitor their credit reports, account and benefit statements for any suspicious activity and to report potential identity theft or fraud to law enforcement, including local police and the state attorney general.

 

At the time of publication, no cyber criminal group had publicly taken credit for the attack on AAWC. The healthcare provider also did not disclose details about the threat actor involved, the extent of the compromised data, or whether it had received any ransom demands.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543