CSIDB logo
Incident

All About Women’s Care

Incident posture

Attack window
Nov 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 10:06

Linked entities

Victim
All About Women’s Care
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Mid-South Pulmonary Sleep Specialists in Tennessee suffered a ransomware attack in November 2025 after suspicious activity was detected on November 2, 2025; Anubis ransomware claimed responsibility and leaked patient data including names, SSNs, medical and financial information.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

All About Women's Care, an obstetrics and gynecology practice based in Englewood, Colorado, experienced a data breach that compromised the personal and protected health information of up to 12,000 patients. The incident involved unauthorized access to the practice's IT environment through an employee virtual private network (VPN) account. An unauthorized actor obtained the credentials for that VPN account and used them to access the network environment. Once inside the network, the actor copied files containing sensitive patient information. The review of those files was completed on June 5, 2026.

The types of data exposed in the breach were extensive and varied by individual, but the confirmed categories included patient names, dates of birth, Social Security numbers, driver's license numbers, other identification numbers, clinical and treatment information, laboratory results, prescription information, provider information, medical documents, ultrasound images, copies of identification documents such as passports, and health insurance information. The broad range of data types involved indicates a comprehensive compromise of protected health information held by the practice.

Following the discovery of suspicious activity, All About Women's Care engaged third-party cybersecurity experts to investigate the incident and confirm the scope of the unauthorized activity. After completing the file review, the practice began notifying the approximately 12,000 affected patients. The breach was reported to the U.S. Department of Health and Human Services' Office for Civil Rights as affecting up to 12,000 individuals. In addition to notifying regulators and patients, the practice stated it is working with cybersecurity professionals to enhance its security posture and prevent similar incidents in the future, and that its policies and procedures related to data privacy and security are being reviewed.

Sources

Sources available to members: 1 source.

CSIDB