Mayo Clinic
ent_019e101318b46d5a97bebe0a9015bd9f
Disclosures
4
HHS OCR · State AG · 2 jurisdictions
Incidents
—
no linked incident in sample
Max affected reported
1,869
nationwide · HHS OCR MN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Mayo Clinic
- Normalized
- mayo clinic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493001OHMD58DCY4635
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- mayoclinic.org
Disclosure history (4)newest first
- MNHHS OCRas victim2025-03-28
Mayo Clinic reported to HHS on 2025-03-28 a Unauthorized Access/Disclosure affecting 1869 individuals. Breached information located on Email. A workforce member emailed PHI (clinical and demographic) to a personal email address and further disclosed it to unauthorized individuals. The CE implemented safeguards and retrained staff.
- 🏎️Indiana State AGas victim2024-01-18
Mayo Clinic reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-28 and was reported on 2024-01-18. 1 Indiana residents were affected. 455 individuals affected in total.
- MNHHS OCRas victim2023-11-03
Mayo Clinic reported to HHS on 2023-11-03 a Unauthorized Access/Disclosure affecting 1152 individuals. Breached information located on Network Server. An employee inadvertently submitted PHI (names, DOB, lab results, MRNs, gender, race, treatment info) to an academic journal, which was then published online. The CE implemented additional administrative safeguards and retrained staff.
- MNHHS OCRas victim2020-10-05
Mayo Clinic (MN) reported to HHS on 2020-10-05 an Unauthorized Access/Disclosure affecting 1,614 individuals. A workforce member impermissibly accessed PHI stored in Electronic Medical Records, including names, addresses, dates of birth, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, media, local law enforcement, and the FBI, and implemented additional technical and administrative safeguards.