June–July 2026: Colorado OB/GYN provider All About Women's Care (AAWC) reported a data breach affecting 12,000 individuals after an unauthorized actor entered its network through an employee VPN account on April 9, 2026, stole files, and attempted to extort the practice, according to a company notice and the HHS OCR breach portal.
What happened
AAWC, which operates locations in Englewood and Littleton, discovered suspicious activity involving an employee VPN login on April 9, 2026. Cybersecurity specialists investigating the event determined that an unauthorized actor accessed AAWC's network, copied certain files, and tried to extort the organization.
The practice completed identifying potentially affected individuals on or about June 5, 2026 and began mailing notifications. HHS OCR lists the breach as a hacking/IT incident on a network server affecting 12,000 people, submitted June 3, 2026. The extortion angle matters: even when a clinic refuses to pay, stolen obstetrics and gynecology files can still circulate on criminal forums if the actor exfiltrated before being cut off.
What data was exposed
Per AAWC's notice as summarized by ClassAction.org, compromised information varies by person and may include:
- Names and dates of birth
- Social Security numbers
- Driver's license or other ID numbers
- Clinical and treatment information
- Lab results and prescription details
- Provider and health insurance information
- Medical documents
- Ultrasound images
- Copies of passports or identification documents
OB/GYN records are among the most sensitive categories in healthcare privacy law: they can reveal pregnancy status, fertility treatment, and conditions patients may not have disclosed outside the exam room. Ultrasound images and ID copies add document-fraud and blackmail risk beyond a typical name-and-email retail leak.
Who is at risk
Current and former patients of All About Women's Care in the Denver south-metro area who received a breach notice—or who visited AAWC for obstetric, gynecologic, or related services around the access window—should assume their chart may have been in scope until the letter says otherwise.
ClassAction.org attorneys opened an investigation into a possible class action; that is separate from AAWC's regulatory notification and does not change the underlying HIPAA disclosure.
What was not stated publicly
The public notice and ClassAction.org summary do not specify whether AAWC paid a ransom, whether the actor published data, or the exact exfiltration volume. The company confirmed unauthorized access, theft of certain files, and an extortion attempt.
Action items for AAWC patients
- Freeze credit at Equifax, Experian, and TransUnion if your notice confirms SSN exposure.
- Watch for OB/GYN-themed phishing—fake appointment reminders, lab-result download links, or "pay your copay" texts citing real clinic names.
- Monitor explanation of benefits for claims tied to women's health services you did not receive.
- Verify any call or email about the breach by contacting AAWC through official channels listed on your notification letter, not reply links.
- Report medical identity theft to your insurer and IdentityTheft.gov if you see suspicious activity.
VPN credentials as the front door
Remote-access VPN accounts remain a common pivot for healthcare intrusions: one compromised employee login can bypass perimeter firewalls entirely. AAWC's case fits a 2026 pattern of specialty clinics—smaller than hospital systems but holding the same HIPAA-grade charts—being targeted for extortion because attackers know ultrasound and ID images are hard to rotate like passwords.
Canonical record
All About Women's Care 2026 breach on BreachHistory.
Sources: ClassAction.org, AAWC breach notice (PDF), HHS OCR breach portal.