Medical Review Institute of America
bd_0d6158d9c6700f78 · schema v1 · pii pii-v1
Full breach record for Medical Review Institute of America →Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack discovered on November 9, 2021. The incident involved the unauthorized acquisition of protected health information (PHI), including demographic data, SSNs, clinical records, and financial information. MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of the stolen data. The company implemented enhanced security measures and offered one year of identity monitoring to affected individuals.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 2, 2021
Begins
Nov 9, 2021
Discovered
May 10, 2022
Filed
vs. sector median
+13 wks slower
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- New Hampshire State AGbd_838ab18b44e7e3882022-03-14 · +57dVerified by operator
- California State AGbd_99bd469703a810be2022-07-13 · +64dVerified by operator
- Maine State AGbd_b7d4763ef84ebad12022-07-13 · +64dVerified by operator
- New Hampshire State AGbd_0419f8046cf11a832022-07-16 · +67dVerified by operator
Show 6 more filings ↓Show fewer ↑up to 146d gap
- New Hampshire State AGbd_f9c8e0a19de550ed2022-07-16 · +67dVerified by operator
- Maine State AGbd_3d174f7229de2ff32022-02-03 · +96dVerified
- California State AGbd_ae43d458dae1f29d2022-02-03 · +96dVerified
- New Hampshire State AGbd_1684aaa6efb0e0ed2022-01-21 · +109dVerified
- HHS OCRbd_1e14ec3cbf1451dc2022-01-20 · +110dVerified by operator
- California State AGbd_9e29b8e3584b22802022-10-03 · +146dVerified by operator
Showing first 10 of 27 linked disclosures.
Filing propagation · 11 filings · 4 states
View merged incident ↗Pattern: first filing Jan 20 (UT), last Oct 3 (CA) — a 256-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 27 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.