On Feb. 26, 2025, Rockhill Women's Care, a full-service OB/GYN medical practice in the Kansas City area, discovered a serious network security incident affecting its IT systems. The breach was quickly identified and, according to the company’s public disclosure, third-party cybersecurity experts were brought in immediately to assess, contain and remediate the situation. Law enforcement was also notified.
The attack has been attributed to the Qilin ransomware group, which claimed responsibility on its dark web portal on March 4, 2025. The group alleged it had obtained 20 GB of sensitive data and threatened to make all of it available for download on March 11, 2025. Screenshots of the stolen data were posted as proof.
After a thorough investigation, which included engaging a data mining vendor to identify affected individuals, Rockhill Women's Care concluded on Aug. 13, 2025, that the compromised data set included both personally identifiable information (PII) and protected health information (PHI).
The exposed information includes names, addresses, dates of birth, Social Security numbers, medical treatment information and health insurance information. While the exact number of affected individuals has not been disclosed, the range of data types involved indicates a high severity, as both identity and medical privacy risks are present.
Rockhill Women's Care responded promptly by engaging cybersecurity professionals to contain the breach and working with law enforcement. The company also initiated a comprehensive review of the impacted data and brought on a data mining vendor to ensure all affected individuals could be notified.
To support those impacted, Rockhill Women's Care has established a dedicated call center at 1-833-855-4208, available Monday through Friday, 8 a.m. to 8 p.m. EST. They have also provided a detailed public notice outlining the incident and offering practical steps for individuals to protect themselves from medical identity theft and related fraud.
Given the nature of the breach, affected individuals should:
The company has stated it is implementing additional security measures to help prevent similar incidents in the future.
A breach notice means your personal details could be circulating far beyond the organization involved. One practical step is continuous monitoring: services such as Identity Defender (included with an ExpressVPN subscription) can automatically check dark-web markets, flag new credit-file activity, and request removal of your information from data-broker sites.
This kind of “early-warning system” can’t undo a breach, but it can help you spot misuse quickly and limit further exposure. ExpressVPN is offering 61% off, risk-free for 30 days, with ID Theft Insurance included and no extra cost for those who sign up for one or two years.