Women's Health USA, Inc.
bd_2e3ec1b65abaf62a · schema v1 · pii pii-v1
Full breach record for Women's Health USA, Inc. →3 incidents on fileWomen's Health USA, Inc. (WHUSA) notified the NH AG of a phishing incident where employee credentials were compromised, allowing unauthorized access to email accounts between April 5 and August 13, 2018. The investigation, completed Feb 15, 2019, revealed potential exposure of patient PII (names, DOB, SSN, Medicare HICNs, health insurance policy numbers, diagnoses, treatment info) for 25 individuals (3 NH residents notified under state law, 22 under HIPAA). WHUSA secured accounts, engaged forensic counsel, and offered credit monitoring.
J jump to incidentP pin to compareR raw source
Incident timeline
Apr 5, 2018
Begins
Feb 15, 2019
Discovered
May 6, 2019
Filed
vs. sector median
on median
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- HHS OCRbd_a113a22db8cb6b382019-03-29 · +38dVerified
- Massachusetts State AGbd_eddbc8d8494c8c8a2019-03-29 · +38dVerified
Filing propagation · 3 filings · 3 states
View merged incident ↗Pattern: first filing Mar 29 (CT), last May 6 (NH) — a 38-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.