Medical Review Institute of America
ent_6f603aab06b80f48881e049e
Disclosures
19
State AG · HHS OCR · 8 jurisdictions
Incidents
2
filings grouped by incident
Max affected reported
172,420
nationwide · HHS OCR UT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Medical Review Institute of America
- Normalized
- medical review institute of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- mrioa.com
Disclosure history (19)newest first
- 🐻California State AGas victim2022-10-03
Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack resulting in the unauthorized acquisition of protected health information (PHI). The incident was discovered on November 9, 2021, with the breach occurring on November 2, 2021. Affected data included demographic information, SSNs, clinical records, and financial/insurance details. MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of the stolen data. Remediation included system hardening, enhanced authentication, and one year of identity monitoring via Kroll.
- ⛰️New Hampshire State AGas victim2022-07-16
State of New Hampshire Attorney General's office filed a breach notification for Medical Review Institute of America on October 7, 2022. The provided source document contains no narrative text or attachment content, preventing extraction of breach details, dates, or affected data types.
- ⛰️New Hampshire State AGas victim2022-07-16
State of New Hampshire Attorney General's office filed a breach notification for Medical Review Institute of America on July 16, 2022. The provided source document contains no narrative text or attachment content, preventing extraction of breach details, dates, or affected data types.
- 🐻California State AGas victim2022-07-13
Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack on November 9, 2021, involving unauthorized acquisition of protected health information (PHI), including names, SSNs, medical history, and insurance details. The breach occurred on November 2, 2021. MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of stolen data. Remediation included enhanced monitoring, new servers, and MFA. Identity monitoring was offered to affected individuals.
- 🦞Maine State AGas victim2022-07-13
Medical Review Institute of America experienced an external system breach (hacking) on November 2, 2021, discovered on November 9, 2021. The incident affected 170,014 individuals, including 293 Maine residents. Acquired data included names and Social Security Numbers. The entity provided written notification and offered 12 months of credit monitoring and identity theft protection through Kroll.
- 🐻California State AGas victim2022-05-10
Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack discovered on November 9, 2021. The incident involved the unauthorized acquisition of protected health information (PHI), including demographic data, SSNs, clinical records, and financial information. MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of the stolen data. The company implemented enhanced security measures and offered one year of identity monitoring to affected individuals.
- 🦞Maine State AGas victim2022-02-03
Medical Review Institute of America reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on November 2, 2021. The breach was discovered on November 9, 2021, and affected 271 Maine residents. The compromised information includes names and Social Security Numbers. The company is offering 12 months of credit monitoring and identity theft protection services through Kroll.
- 🐻California State AGas victim2022-02-03
Medical Review Institute of America (MRIoA) disclosed a cyber-attack on November 9, 2021, involving unauthorized access to protected health information (PHI) and personal data (SSN, DOB, demographics). MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of exfiltrated data. Remediation included enhanced authentication, new servers, and Kroll-provided identity monitoring for affected individuals.
- 🌴South Carolina State AGas reporting2022-01-24
Medical Review Institute of America (MRIoA) notified South Carolina Public Employee Benefit (PEBA) of a cyber-attack discovered on November 9, 2021. The incident involved unauthorized access to systems containing protected health information (PHI), including names, SSNs, and medical history. MRIoA engaged forensic experts, contacted the FBI, and confirmed deletion of exfiltrated data. Affected individuals received one year of identity monitoring via Kroll. No evidence of misuse was found at the time of notification.
- UTHHS OCRas victim2022-01-20
Medical Review Institute of America reported to HHS on 2022-01-20 a Hacking/IT Incident affecting 2406 individuals. Breached information located on Network Server. The business associate implemented additional administrative and technical safeguards and provided complimentary credit monitoring services to affected individuals.
- 🦞Maine State AGas victim2022-01-18
Medical Review Institute of America reported an external system breach (hacking) occurring on November 2, 2021, discovered on November 9, 2021. The incident compromised the names and Social Security Numbers of approximately 157,885 individuals, including 269 Maine residents. The entity notified affected individuals in writing on January 20, 2022, and provided 12 months of credit monitoring and identity theft protection services.
- 🐻California State AGas victim2022-01-18
Medical Review Institute of America (MRIoA) disclosed a cyber-attack discovered on November 9, 2021, involving unauthorized access to protected health information (PHI) including names, SSNs, medical history, and insurance details. The breach occurred on November 2, 2021. MRIoA engaged forensic experts, notified the FBI, and deleted the stolen data. Affected individuals were offered one year of identity monitoring via Kroll.
- 🦫Oregon State AGas victim2022-01-10
Medical Review Institute of America (MRIoA) reported a data breach to the Oregon Attorney General. The breach was reported on 2022-01-10. The breach occurred during 11/2/2021 - 11/9/2021. The breach was discovered on 11/9/2021. Notice was sent on 1/7/2022.
- 🌴South Carolina State AGas victim2022-01-10
Medical Review Institute of America (MRIoA) disclosed a cyber-attack discovered on November 9, 2021, involving unauthorized access to protected health information (PHI) and personal data (SSN, DOB, demographics). MRIoA engaged forensic experts and the FBI, retrieved exfiltrated data, and confirmed its deletion. Affected individuals received one year of credit monitoring via Kroll. Remediation included enhanced authentication, new servers, and policy updates. No evidence of misuse was found at the time of notification.
- 🦞Maine State AGas victim2022-01-07
Medical Review Institute of America, a healthcare organization, reported an external system breach (hacking) that occurred on November 2, 2021, and was discovered on November 9, 2021. The breach affected 194 Maine residents, compromising their names and Social Security numbers. The company notified affected individuals on January 7, 2022, and offered 12 months of credit monitoring and identity theft protection services.
- 🌲Washington State AGas victim2022-01-07
Medical Review Institute of America, a health sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-11-09 and filed notice on 2022-01-07. 3,225 Washington residents were affected. 59 days elapsed between awareness and notification. 7 days to identify the breach. 0 days to contain the breach.
- 🐻California State AGas victim2022-01-07
Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack resulting in the unauthorized acquisition of protected health information (PHI). The incident was discovered on November 9, 2021, with the breach occurring on November 2, 2021. Affected data included demographic information, social security numbers, clinical information, and financial information. MRIoA engaged forensic experts, notified the FBI, and confirmed the deletion of the stolen data. The company implemented additional cybersecurity safeguards and offered one year of identity monitoring to affected individuals.
- UTHHS OCRas victim2022-01-07
Medical Review Institute of America reported to HHS on 2022-01-07 a Hacking/IT Incident affecting 172,420 individuals. Breached information located on Network Server. The business associate implemented additional administrative and technical safeguards and provided complimentary credit monitoring services.
- 🦬Montana State AGas victim2022-01-07
Medical Review Institute of America reported a data breach to the Montana Attorney General. The breach was reported on 2022-01-07. The breach occurred from 11/9/2021 to 11/16/2021. 404 Montana residents were affected.