DisclosureLens
Social EngineeringHealthcareTechnologyHealthcarePhishingStolen CredentialsData ExfiltratedCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDHealth (basic)Financial accountMediumContained

Women's Health USA, Inc.

bd_2e3ec1b65abaf62a · schema v1 · pii pii-v1

Severity

Medium

Discovered

Feb 15, 2019

Filed

May 6, 2019

To disclose

11 weeks

Affected · nationwide

253 in this filing

Linked

3 filings

Confidence

64%
Full breach record for Women's Health USA, Inc.3 incidents on file

Women's Health USA, Inc. (WHUSA) notified the NH AG of a phishing incident where employee credentials were compromised, allowing unauthorized access to email accounts between April 5 and August 13, 2018. The investigation, completed Feb 15, 2019, revealed potential exposure of patient PII (names, DOB, SSN, Medicare HICNs, health insurance policy numbers, diagnoses, treatment info) for 25 individuals (3 NH residents notified under state law, 22 under HIPAA). WHUSA secured accounts, engaged forensic counsel, and offered credit monitoring.

Incident timeline

undetected · 316 days
discovery → filing · 11 weeks / 80 days

Apr 5, 2018

Begins

Feb 15, 2019

Discovered

May 6, 2019

Filed

vs. sector median

on median

This filing is one of 3 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
HHS OCRMar 29 · first
Massachusetts State AGMar 29 · first
New Hampshire State AG+38d · this page

Pattern: first filing Mar 29 (CT), last May 6 (NH) — a 38-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.