Grand River Medical Group
bd_a7d66cecca5a4d51 · schema v1 · pii pii-v1
Full breach record for Grand River Medical Group →Grand River Medical Group (Iowa) reported to HHS on 2021-02-12 a Hacking/IT Incident (email phishing) affecting 37,423 individuals. An employee was the victim of a phishing attack that compromised PHI including names, addresses, Social Security numbers, dates of birth, claims information, medications, and other treatment information. No business associate was involved. The CE notified HHS, individuals, and media; offered credit monitoring; strengthened technical safeguards; and retrained staff on email security. OCR provided HIPAA Security Rule technical assistance.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Feb 12, 2021
Filed
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Maine State AGbd_b1dfa9db3f8119582021-02-12Candidate
- Montana State AGbd_8ce8af789d4021bc2021-02-08 · +4dCandidate
- Indiana State AGbd_e7e1c1c71ed3b46c2021-02-08 · +4dVerified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.