Social EngineeringPhishingCustomer Data InvolvedEmployee Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMINORMediumContained
MEDNAX Services, Inc.
bd_11476f6352fa2626 · schema v1 · pii pii-v1
Full breach record for MEDNAX Services, Inc. →MEDNAX Services, Inc. reported a data security event where an unauthorized third party accessed a Microsoft Office 365 business email account via phishing. The breach occurred between July 2 and July 3, 2020. Affected data may include patient contact information, Social Security numbers, health insurance details, medical records, and billing information. MEDNAX engaged a forensic firm, reset passwords, and offered one year of identity monitoring to affected individuals.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1253ca6eeacfa879California State AGfiled 2020-12-16(7d gap)Candidate
- bd_2317d15fb2fdc537HHS OCRfiled 2020-12-16(7d gap)Candidate
- bd_3c1d1683a865d956Montana State AGfiled 2020-12-16(7d gap)Verified
- bd_cc27b0970ea64726Oregon State AGfiled 2020-12-16(7d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_ef1f98abb4d60c8eWashington State AGfiled 2020-12-16(7d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197488
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 23, 2020
- Raw hash
- 94dd865a8a8f3078db178a265d66afabbd3236094fdeb0d1a3754eac4511410b
Reporting entity
- Name
- MEDNAX Services, Inc.norm: mednax services
Victim entity
- Name
- MEDNAX Services, Inc.norm: mednax services
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Dec 23, 2020
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMINOR
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing LinkT1114 Email Collection
- Threat actor
- External
- Initial access
- phishing_link
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.