Women's Health USA, Inc.
ent_b91782073cde6ec0ff913f6a
Disclosures
5
State AG · HHS OCR · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
17,531
nationwide · HHS OCR CT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Women's Health USA, Inc.
- Normalized
- women s health usa— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (5)newest first
- New Hampshire State AGas victim2019-05-06
Women's Health USA, Inc. (WHUSA) notified the NH AG of a phishing incident where employee credentials were compromised, allowing unauthorized access to email accounts between April 5 and August 13, 2018. The investigation, completed Feb 15, 2019, revealed potential exposure of patient PII (names, DOB, SSN, Medicare HICNs, health insurance policy numbers, diagnoses, treatment info) for 25 individuals (3 NH residents notified under state law, 22 under HIPAA). WHUSA secured accounts, engaged forensic counsel, and offered credit monitoring.
- CONNECTICUTHHS OCRas victim2019-03-29
Women’s Health USA, Inc. reported to HHS on 2019-03-29 a Hacking/IT Incident affecting 17,531 individuals. Breached information located on Desktop Computer, Email. A phishing attack targeted employee emails, resulting in unauthorized auto-forwarding of PHI including names, DOBs, SSNs, and treatment info. CE implemented 2FA, retrained staff, and disabled forwarding.
- Massachusetts State AGas victim2019-03-29
Women's Health USA, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-03-29. 15 Massachusetts residents were affected. The report records the breach type as electronic.
- Illinois State AGas victim2019-01-01
WOMENS HEALTH USA INC filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-206). The register records the breach as discovered on March 29, 2019. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Illinois State AGas victim2019-01-01
WOMENS HEALTH USA INC filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-174). The register records the breach as discovered on April 5, 2018. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.