
American Association of Critical-Care Nurses said a data security incident it suffered earlier this year compromised the sensitive personal data of nearly 60,000 customers.
Based in Aliso Viejo, California, the American Association of Critical-Care Nurses (AACN) is a professional organisation committed to advancing critical care nursing. It offers education, resources, and support to nurses in critical care settings, fostering excellence in both patient care and professional growth.
In a data security incident notice filed with the Maine Attorney General’s Office, the American Association of Critical-Care Nurses (AACN) reported discovering suspicious activity earlier this year involving its website’s payment system. The healthcare service provider company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
“On July 31, 2025, our investigation identified evidence that an unauthorised party accessed payment card information associated with certain transactions on our site beginning on March 8, 2025. While our investigation is unable to determine exactly which payment cards may have been accessed by the unauthorised party, we are notifying you out of an abundance of caution, as we have a record of you making a purchase on the AACN site during the relevant time period,” AACN said.
The compromised data included card numbers, expiry dates, CVVs, names, shipping and billing addresses, phone numbers, and email addresses associated with a transaction on the AACN site. The filing with the Maine state regulator also states that the company has identified at least 57,526 individuals impacted by the incident.
“In response to the issue, we took steps to secure the payment system and have since implemented further security enhancements to help remediate the issue. We take the security of our customers’ and members’ information very seriously, and are continuing to enhance our safeguards to help prevent similar issues from occurring in the future,” the company added.
AACN has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered two years of complimentary identity protection and credit monitoring services through IDX to all affected individuals.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543