Grand River Medical Group
bd_a7d66cecca5a4d51 · schema v1 · pii pii-v1
Full breach record for Grand River Medical Group →Grand River Medical Group (Iowa) reported to HHS on 2021-02-12 a Hacking/IT Incident (email phishing) affecting 37,423 individuals. An employee was the victim of a phishing attack that compromised PHI including names, addresses, Social Security numbers, dates of birth, claims information, medications, and other treatment information. No business associate was involved. The CE notified HHS, individuals, and media; offered credit monitoring; strengthened technical safeguards; and retrained staff on email security. OCR provided HIPAA Security Rule technical assistance.
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_b1dfa9db3f811958Maine State AGfiled 2021-02-12Candidate
- bd_8ce8af789d4021bcMontana State AGfiled 2021-02-08(4d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 12, 2021
- Raw hash
- dc4b60758f840bdde532889e5f9ee9c696036478000cbd273dea196d0d924a07
Source filing
Reporting entity
- Name
- Grand River Medical Groupnorm: grand river medical
- Industry
- Health Care Services
Victim entity
- Name
- Grand River Medical Groupnorm: grand river medical
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 37,423
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1566 PhishingT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- OCR provided the CE with technical assistance regarding its HIPAA Security Rule obligations.
- Initial access
- phishing_link
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.