Mayfield Clinic Inc
bd_4b5729ab94807e51 · schema v1 · pii pii-v1
Full breach record for Mayfield Clinic Inc →An unauthorized person sent a fraudulent email with an attachment that triggered a download of a ransomware virus to 23,341 email addresses held by Mayfield Clinic Inc's business associate (BA) on its behalf. The protected health information (PHI) involved in the breach included email addresses. The company sent an email notification to affected individuals on the day of the incident and sent another email notification two days later. The company provided breach notification to HHS, affected individuals, and the media and also posted substitute notice on its web site. Following the breach, the company assessed system controls, provided anti-scanning updates to its employees’ email, deleted the email addresses it maintained on its BA’s systems, and put a hold on the future electronic distribution of newsletters. OCR obtained written assurances that the company implemented the corrective actions.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Apr 23, 2016
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.