HackingData ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Medical Review Institute of America
bd_0d6158d9c6700f78 · schema v1 · pii pii-v1
Full breach record for Medical Review Institute of America →Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack discovered on November 9, 2021. The incident involved the unauthorized acquisition of protected health information (PHI), including demographic data, SSNs, clinical records, and financial information. MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of the stolen data. The company implemented enhanced security measures and offered one year of identity monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-553273
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 10, 2022
- Raw hash
- 28d985d413110b4c1887a8022236678f028942fede8d4c855b157a48bffc7a89
Reporting entity
- Name
- Medical Review Institute of Americanorm: medical review institute of america
- Domain
- mrioa.com
Victim entity
- Name
- Medical Review Institute of Americanorm: medical review institute of america
- Domain
- mrioa.com
Incident
- Discovered
- Nov 9, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Contacted the FBI
Compliance
- Time to disclose
- 26 weeks(182 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.