Mayfield Clinic Inc
bd_4b5729ab94807e51 · schema v1 · pii pii-v1
Full breach record for Mayfield Clinic Inc →An unauthorized person sent a fraudulent email with an attachment that triggered a download of a ransomware virus to 23,341 email addresses held by Mayfield Clinic Inc's business associate (BA) on its behalf. The protected health information (PHI) involved in the breach included email addresses. The company sent an email notification to affected individuals on the day of the incident and sent another email notification two days later. The company provided breach notification to HHS, affected individuals, and the media and also posted substitute notice on its web site. Following the breach, the company assessed system controls, provided anti-scanning updates to its employees’ email, deleted the email addresses it maintained on its BA’s systems, and put a hold on the future electronic distribution of newsletters. OCR obtained written assurances that the company implemented the corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 23, 2016
- Raw hash
- f4713d76a8a1eae10b603207d3ba1e6d66cfc1d326ca559e7b29c9550f27ec52
Source filing
Reporting entity
- Name
- Mayfield Clinic Incnorm: mayfield clinic
- Industry
- Health Care Services
Victim entity
- Name
- Mayfield Clinic Incnorm: mayfield clinic
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 23,341
- Data types
- HEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- Regulator citations
- Provided breach notification to HHSOCR obtained written assurances that the CE implemented the corrective actions
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.