HackingData ExfiltratedCustomer Data InvolvedPHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
Medical Review Institute of America
bd_99bd469703a810be · schema v1 · pii pii-v1
Full breach record for Medical Review Institute of America →Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack on November 9, 2021, involving unauthorized acquisition of protected health information (PHI), including names, SSNs, medical history, and insurance details. The breach occurred on November 2, 2021. MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of stolen data. Remediation included enhanced monitoring, new servers, and MFA. Identity monitoring was offered to affected individuals.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_0419f8046cf11a83New Hampshire State AGfiled 2022-07-16(3d gap)Verified
- bd_f9c8e0a19de550edNew Hampshire State AGfiled 2022-07-16(3d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-555249
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 13, 2022
- Raw hash
- d67597742dec2e4e363656a096a0afd3fa6e2375807a6cb99099478ad7ddda96
Reporting entity
- Name
- Medical Review Institute of Americanorm: medical review institute of america
- Domain
- mrioa.com
Victim entity
- Name
- Medical Review Institute of Americanorm: medical review institute of america
- Domain
- mrioa.com
Incident
- Discovered
- Nov 9, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PHIIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Contacted the FBI
Compliance
- Time to disclose
- 35 weeks(246 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.