Medical Review Institute of America
bd_1684aaa6efb0e0ed · schema v1 · pii pii-v1
Full breach record for Medical Review Institute of America →Medical Review Institute of America (MRIoA) filed a supplemental breach notification with the New Hampshire Attorney General on January 18, 2022, identifying 89 additional NH residents affected, bringing the total to 435. The incident, a sophisticated cyber-attack discovered on November 9, 2021, involved unauthorized access and data acquisition. Affected data included PHI, SSNs, and financial info. MRIoA engaged forensic experts, notified the FBI, and provided one year of Kroll identity monitoring to victims.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 9, 2021
Discovered
Jan 21, 2022
Filed
vs. sector median
2 wks faster
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- HHS OCRbd_1e14ec3cbf1451dc2022-01-20 · +1dVerified by operator
- Maine State AGbd_3d174f7229de2ff32022-02-03 · +13dVerified
- California State AGbd_ae43d458dae1f29d2022-02-03 · +13dVerified
- New Hampshire State AGbd_838ab18b44e7e3882022-03-14 · +52dVerified by operator
Show 6 more filings ↓Show fewer ↑up to 255d gap
- California State AGbd_0d6158d9c6700f782022-05-10 · +109dVerified by operator
- California State AGbd_99bd469703a810be2022-07-13 · +173dVerified by operator
- Maine State AGbd_b7d4763ef84ebad12022-07-13 · +173dVerified by operator
- New Hampshire State AGbd_0419f8046cf11a832022-07-16 · +176dVerified by operator
- New Hampshire State AGbd_f9c8e0a19de550ed2022-07-16 · +176dVerified by operator
- California State AGbd_9e29b8e3584b22802022-10-03 · +255dVerified by operator
Showing first 10 of 27 linked disclosures.
Filing propagation · 11 filings · 4 states
View merged incident ↗Pattern: first filing Jan 20 (UT), last Oct 3 (CA) — a 256-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 27 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.