Mayo Clinic
ent_019e101318b46d5a97bebe0a9015bd9f
Disclosures
7
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
1,902
nationwide · HHS OCR MN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Mayo Clinic
- Normalized
- mayo clinic— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493001OHMD58DCY4635
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- mayoclinic.org
Disclosure history (7)newest first
- MINNESOTAHHS OCRas victim2025-03-28
Mayo Clinic reported to HHS on 2025-03-28 a Unauthorized Access/Disclosure affecting 1869 individuals. Breached information located on Email. A workforce member emailed PHI (clinical and demographic) to a personal email address and further disclosed it to unauthorized individuals. The CE implemented safeguards and retrained staff.
- Massachusetts State AGas victim2024-02-08
Mayo Clinic reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2024-02-08. 2 Massachusetts residents were affected.
- Indiana State AGas victim2024-01-18
Mayo Clinic reported a data breach to the Indiana Attorney General. The breach occurred on 2023-05-28 and was reported on 2024-01-18. 1 Indiana residents were affected. 455 individuals affected in total.
- MINNESOTAHHS OCRas victim2023-11-03
Mayo Clinic reported to HHS on 2023-11-03 a Unauthorized Access/Disclosure affecting 1152 individuals. Breached information located on Network Server. An employee inadvertently submitted PHI (names, DOB, lab results, MRNs, gender, race, treatment info) to an academic journal, which was then published online. The CE implemented additional administrative safeguards and retrained staff.
- MINNESOTAHHS OCRas victim2020-10-05
Mayo Clinic (MN) reported to HHS on 2020-10-05 an Unauthorized Access/Disclosure affecting 1,614 individuals. A workforce member impermissibly accessed PHI stored in Electronic Medical Records, including names, addresses, dates of birth, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, media, local law enforcement, and the FBI, and implemented additional technical and administrative safeguards.
- MINNESOTAHHS OCRas victim2019-03-22
Mayo Clinic reported to HHS on 2019-03-22 a Unauthorized Access/Disclosure affecting 1902 individuals. Breached information located on Other. An update to its mobile application software enabled users to access the ePHI of 1,902 individuals, including names, addresses, dates of birth, diagnoses, lab results, and medications. The CE notified HHS, affected individuals, and the media, and revised the software to fix the error.
- MINNESOTAHHS OCRas victim2010-09-08
Mayo Clinic reported to HHS on 2010-09-08 a Theft affecting 1740 individuals. Breached information located on Electronic Medical Record. An employee impermissibly accessed PHI for a period of 4 years.