Social EngineeringPhishingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICMediumContained
MEDNAX Services, Inc.
bd_1253ca6eeacfa879 · schema v1 · pii pii-v1
Full breach record for MEDNAX Services, Inc. →MEDNAX Services, Inc. reported a phishing incident affecting business email accounts between June 17 and June 22, 2020. Discovered on June 19, 2020, the breach impacted a small number of accounts, potentially exposing patient PII, SSNs, and health information. 45 Rhode Island residents were notified. MEDNAX engaged forensic investigators, reset passwords, and offered one year of identity monitoring.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_2317d15fb2fdc537HHS OCRfiled 2020-12-16Candidate
- bd_3c1d1683a865d956Montana State AGfiled 2020-12-16Verified
- bd_cc27b0970ea64726Oregon State AGfiled 2020-12-16Verified
- bd_ef1f98abb4d60c8eWashington State AGfiled 2020-12-16Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_11476f6352fa2626California State AGfiled 2020-12-23(7d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-197246
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 16, 2020
- Raw hash
- 793d84008ff18d32ed08762cfab3a94831d5b584aadf410587826a25599e5b40
Reporting entity
- Name
- MEDNAX Services, Inc.norm: mednax services
Victim entity
- Name
- MEDNAX Services, Inc.norm: mednax services
Incident
- Discovered
- Jun 19, 2020
- Materiality determined
- Dec 16, 2020
- Notification sent
- —
- Affected individuals
- 45
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASIC
- Attack vector
- Phishing
- MITRE ATT&CK
- T1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Initial access
- phishing_link
Compliance
- Time to disclose
- 26 weeks(180 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.