Menninger Clinic
ent_006a3e03d9996779d86770b8
Disclosures
9
Leak Site · State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,076
nationwide · State AG ME
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- Menninger Clinic
- Normalized
- menninger clinic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- menningerclinic.org
Disclosure history (9)newest first
- GLOBALLeak Siteas victim2024-09-12
Despite repeated attempts to contact menningerclinic.org we were ignored. The negligence of the management of this organization surprised us. This leaves us with no choice but to start publishing data. Menningerclinic.org has 72 hours to contact us and resolve the situation without exposing their employees to the problems they will face.
- Maine State AGas victim2021-10-04
The Menninger Clinic, a healthcare organization, reported a data breach to the Maine Attorney General, which was discovered on July 26, 2021. The breach, an external system hacking incident that occurred on March 18, 2021, affected three Maine residents and a total of 2,076 individuals. The compromised information included names in combination with financial account numbers or credit/debit card numbers and their security codes. The clinic notified the affected individuals on September 24, 2021, and offered 12 months of identity theft protection services through IDX.
- Massachusetts State AGas victim2021-10-04
The Menninger Clinic reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-10-04. 5 Massachusetts residents were affected. The report records the breach type as electronic.
- New Hampshire State AGas victim2021-10-01
The Menninger Clinic, a psychiatric hospital in Houston, Texas, notified the New Hampshire Attorney General of a data security incident discovered on March 30, 2021. Unauthorized access to employee email accounts resulted in the exposure of personal and health information for one New Hampshire resident. The clinic engaged cybersecurity firms, reported the incident to federal and local law enforcement, and implemented enhanced security measures including multi-factor authentication.
- Maine State AGas victim2021-09-28
The Menninger Clinic, a healthcare organization, reported an external system breach that occurred on March 18, 2021, and was discovered on July 26, 2021. The incident affected 2,076 individuals, compromising names and financial account numbers with associated access credentials. The clinic notified affected individuals on September 24, 2021, and offered 12 months of credit and identity monitoring services through IDX.
- TEXASHHS OCRas victim2021-09-24
The Menninger Clinic reported to HHS on 2021-09-24 a Hacking/IT Incident affecting 1365 individuals. Breached information located on Email. Employees were victims of an email phishing scheme exposing PHI including names, DOB, addresses, SSNs, and medical/financial data. Response included credit monitoring, security safeguards, and staff retraining.
- Indiana State AGas victim2021-09-24
The Menninger Clinic reported a data breach to the Indiana Attorney General. The breach occurred on 2021-03-18 and was reported on 2021-09-24. 8 Indiana residents were affected. 2,076 individuals affected in total.
- Montana State AGas victim2021-09-24
The Menninger Clinic notified Montana AG of a March 30, 2021 incident where employee email accounts were accessed without authorization, likely via phishing. Personal information (names) transmitted via email was potentially impacted. Menninger engaged forensic investigators, notified law enforcement (FBI, DHS), and offered identity protection services.
- Illinois State AGas victim2021-01-01
THE MENNINGER CLINIC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-400). The register records the breach as discovered on March 30, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.