About Women OB/Gyn Data Breach Exposes PHI and PII

Published
September 1, 2026
Updated
September 1, 2026
About Women OB/Gyn Data Breach Exposes PHI and PII
About Women Ob-gyn

About Women OB/Gyn PC, a private obstetrics and gynecology practice in Northern Virginia, disclosed a data breach involving highly sensitive patient information. The practice, which serves patients in areas including Woodbridge, Lorton and Stafford, discovered the breach in December 2025.

The breach was disclosed to the Massachusetts Office of Consumer Affairs and Business Regulation on Aug. 27, 2026. About Women OB/Gyn also posted a notice on its website with details about the incident.

About Women OB/Gyn became aware of unusual activity in its network environment on or about Dec. 7, 2025. The practice began an investigation and retained legal counsel and third-party forensic specialists to look into the suspicious activity.

The investigation revealed that certain information may have been viewed and copied by an unauthorized individual. The unauthorized activity occurred between Dec. 1, 2025, and Dec. 7, 2025.

After identifying the intrusion, the practice began a comprehensive review of the affected data to determine what sensitive or personal information was potentially impacted and to whom it related.

On Aug. 13, 2026, the practice finished its review of the potentially impacted information. About Women OB/Gyn began notifying consumers on Aug. 27, 2026.

The types of information exposed varied by individual but may include names, dates of birth, Social Security numbers, financial account numbers, financial account access information, payment card numbers, passport numbers, military identification numbers, medical record numbers, Medicare/Medicaid numbers, health insurance identification or group numbers, medical information and patient identification or account numbers.

On Jan. 8, 2026, a ransomware group known as Anubis posted a claim on the dark web, stating it had obtained the practice's data.

About Women OB/Gyn's response to the breach

About Women OB/Gynis offering affected individuals 12 months of free credit monitoring, credit report and credit score services. These services are provided through Cyberscout, a TransUnion company. The practice is also providing proactive fraud assistance to help individuals who have questions or who become victims of fraud.

To enroll, affected individuals must visit the Cyberscout activation page and enter the unique code included in their notification letter. Enrollment must be completed within 90 days of the letter's date.

For questions or additional information, individuals can call the dedicated assistance line at 1-866-898-9420, Monday through Friday from 8 a.m. to 8 p.m. Eastern Time, excluding major U.S. holidays. Callers should have their notification letter ready.

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
About Women Ob-gyn
Consumers Notification date
Date of Breach
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Medical Records
  • name
  • date of birth
  • financial account number
  • financial account access information
  • medical record number
  • Medicare/Medicaid number
  • health insurance identification or group number
  • medical information
  • patient identification
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image