All About Women’s Care
Incident posture
Linked entities
- Victim
- All About Women’s Care
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Mid-South Pulmonary Sleep Specialists in Tennessee suffered a ransomware attack in November 2025 after suspicious activity was detected on November 2, 2025; Anubis ransomware claimed responsibility and leaked patient data including names, SSNs, medical and financial information.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
All About Women's Care, an obstetrics and gynecology practice based in Englewood, Colorado, experienced a data breach that compromised the personal and protected health information of up to 12,000 patients. The incident involved unauthorized access to the practice's IT environment through an employee virtual private network (VPN) account. An unauthorized actor obtained the credentials for that VPN account and used them to access the network environment. Once inside the network, the actor copied files containing sensitive patient information. The review of those files was completed on June 5, 2026.
The types of data exposed in the breach were extensive and varied by individual, but the confirmed categories included patient names, dates of birth, Social Security numbers, driver's license numbers, other identification numbers, clinical and treatment information, laboratory results, prescription information, provider information, medical documents, ultrasound images, copies of identification documents such as passports, and health insurance information. The broad range of data types involved indicates a comprehensive compromise of protected health information held by the practice.
Following the discovery of suspicious activity, All About Women's Care engaged third-party cybersecurity experts to investigate the incident and confirm the scope of the unauthorized activity. After completing the file review, the practice began notifying the approximately 12,000 affected patients. The breach was reported to the U.S. Department of Health and Human Services' Office for Civil Rights as affecting up to 12,000 individuals. In addition to notifying regulators and patients, the practice stated it is working with cybersecurity professionals to enhance its security posture and prevent similar incidents in the future, and that its policies and procedures related to data privacy and security are being reviewed.
Sources
Sources available to members: 1 source.