
Women’s Wellness of Southern Delaware, an obstetrics, gynecology and facial aesthetics practice based in Lewes, Delaware, has disclosed a data security incident tied to a former provider who retained patient information after departing the practice.
The practice said it learned on April 28, 2026, that the former provider had kept patient contact details and other patient-related records following the end of their engagement. During the provider’s time at the practice, the individual had access to the electronic medical records system used by Women’s Wellness of Southern Delaware, though the information retained after departure was not obtained through that access.
The practice said it believes the former provider used the retained information to reach out to some patients and offer similar aesthetic services through a new practice.
Two categories of patients were affected. For patients who received aesthetics services, the exposed information may have included names, email addresses, birth dates, gender, home addresses, phone numbers, medications and supplements, allergy records, photographs, intake records, aesthetics-related medical history, face maps, and dates and descriptions of services or products purchased.
A more limited set of clinical services patients was also affected. For this group, the exposed information may have included names, phone numbers, purchase dates, and descriptions of items or medications bought.
Women’s Wellness of Southern Delaware began notifying affected patients on June 26, 2026, through a public notice distributed via PR Newswire. The practice also submitted a disclosure to the New Hampshire Attorney General’s office, dated June 29, 2026.
The practice said it is in contact with the former provider and is working to secure confirmation that the retained data has been returned or destroyed. It also said it has implemented additional data privacy and security measures to guard against similar incidents going forward.
The incident had not yet appeared on the U.S. Department of Health and Human Services’ Office for Civil Rights breach reporting portal as of the disclosure, leaving the total number of affected individuals unconfirmed.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543