MEDNAX Services, Inc.
ent_a3c396681b17958fbb1513a0
Disclosures
9
State AG · HHS OCR · 8 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
1,442,997
nationwide · HHS OCR FL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MEDNAX Services, Inc.
- Normalized
- mednax services— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (9)newest first
- New Hampshire State AGas victim2021-01-12
North American Partners in Anesthesia (NAPA) notified the New Hampshire Attorney General of a security incident involving its business associate, MEDNAX Services, Inc. An unauthorized party accessed MEDNAX's Microsoft Office 365 email system between June 17 and June 22, 2020, via phishing. The attacker attempted payroll fraud but was unsuccessful. Patient and guarantor information (names, SSNs, health insurance details, medical records) was stored in compromised accounts. 109 New Hampshire residents were affected. NAPA offered one year of credit monitoring. The incident was contained by resetting passwords and adding authentication requirements.
- Illinois State AGas victim2021-01-01
MEDNAX SERVICES, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-009). The register records the breach as discovered on May 6, 2020. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Massachusetts State AGas victim2020-12-23
MEDNAX Services, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2020-12-23. 2 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2020-12-23
MEDNAX Services, Inc. reported a data security event where an unauthorized third party accessed a Microsoft Office 365 business email account via phishing. The breach occurred between July 2 and July 3, 2020. Affected data may include patient contact information, Social Security numbers, health insurance details, medical records, and billing information. MEDNAX engaged a forensic firm, reset passwords, and offered one year of identity monitoring to affected individuals.
- California State AGas victim2020-12-16
MEDNAX Services, Inc. disclosed that an unauthorized third party gained access to certain Microsoft Office 365-hosted business email accounts via phishing between June 17 and June 22, 2020. The incident was discovered on June 19, 2020. Personal information of 45 Rhode Island residents, including PHI, SSNs, and financial data, may have been accessed. MEDNAX engaged forensic investigators, reset passwords, and offered one year of identity monitoring.
- FLORIDAHHS OCRas victim2020-12-16
MEDNAX Services, Inc. (now Pediatrix Medical Group), acting as a HIPAA Business Associate, reported to HHS OCR on 2020-12-16 that an email phishing attack compromising multiple employee mailboxes exposed PHI of 1,442,997 individuals. Affected data included names, addresses, dates of birth, driver's license numbers, Social Security numbers, health insurance information, claims/financial information, and treatment information. The entity notified HHS, affected individuals, media, and provided substitute notice; remediation included additional technical safeguards and staff retraining on email security.
- Montana State AGas victim2020-12-16
MEDNAX Services, Inc. notified Montana residents of a phishing incident in early 2020 that compromised a business email account. Patient data potentially exposed included names, SSNs, DOBs, medical records, and financial info. MEDNAX reset passwords, engaged forensic investigators, and offered one year of identity monitoring.
- Oregon State AGas victim2020-12-16
MEDNAX Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-12-16. The breach occurred during 6/17/2020 - 6/22/2020. The breach was discovered on 6/19/2020. 2,411 individuals were affected. Notice was sent on 12/16/202012/17/202012/18/2020.
- Washington State AGas victim2020-12-16
MEDNAX Services, Inc. notified Washington AG of a phishing incident where unauthorized parties accessed business email accounts between June 17-22, 2020. Discovered June 19, 2020. Notifications sent Dec 16, 2020. Affected ~29,861 WA residents. Data potentially included PII, SSNs, health insurance, and medical info.