Menu
Browse

Womens Health USA

Primary URL Location Industry
www[.]whusa[.]com
Country United States of America
Healthcare Icon
Healthcare
Profile

Womens Health USA operates as a healthcare business associate, providing services that involve the handling of protected health information on behalf of covered entities such as health plans, providers, and clearinghouses. Its core activities likely include administrative, billing, or data management functions that require access to patient records. The organization is headquartered in the United States, with a noted presence in Connecticut where the 2018 incident occurred. As a business associate, it is subject to the Health Insurance Portability and Accountability Act (HIPAA) and must implement safeguards to protect the confidentiality, integrity, and availability of the health information it processes. Its role positions it within the broader healthcare support sector, focusing on enabling covered entities to comply with regulatory requirements while delivering their clinical or administrative services.

In April 2018, Womens Health USA experienced a phishing attack that compromised employee email accounts, leading to a potential breach of protected health information. The breach exposed patient names, treatment-related details, and for a smaller subset, Social Security numbers and medical insurance data. Following a months-long forensic investigation, the organization issued breach notifications to more than 17,000 individuals whose information may have been accessed. Because it functions as a business associate, the breach required coordinated disclosure with the covered entities it serves, in accordance with HIPAA breach notification rules. The incident highlighted the organization’s vulnerability to social engineering threats and prompted a review of its email security controls and employee awareness training.

Incidents
Linked incidents available to members
1 incident