MEDNAX Services, Inc.
ent_a3c396681b17958fbb1513a0
Disclosures
7
State AG · HHS OCR · 6 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
1,442,997
as filed · HHS OCR FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- MEDNAX Services, Inc.
- Normalized
- mednax services— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (7)newest first
- 🐻California State AGas victim2020-12-23
MEDNAX Services, Inc. reported a data security event where an unauthorized third party accessed a Microsoft Office 365 business email account via phishing. The breach occurred between July 2 and July 3, 2020. Affected data may include patient contact information, Social Security numbers, health insurance details, medical records, and billing information. MEDNAX engaged a forensic firm, reset passwords, and offered one year of identity monitoring to affected individuals.
- 🐻California State AGas victim2020-12-16
MEDNAX Services, Inc. reported a phishing incident affecting business email accounts between June 17 and June 22, 2020. Discovered on June 19, 2020, the breach impacted a small number of accounts, potentially exposing patient PII, SSNs, and health information. 45 Rhode Island residents were notified. MEDNAX engaged forensic investigators, reset passwords, and offered one year of identity monitoring.
- FEDERALHHS OCRas victim2020-12-16
MEDNAX Services, Inc. (now Pediatrix Medical Group), acting as a HIPAA Business Associate, reported to HHS OCR on 2020-12-16 that an email phishing attack compromising multiple employee mailboxes exposed PHI of 1,442,997 individuals. Affected data included names, addresses, dates of birth, driver's license numbers, Social Security numbers, health insurance information, claims/financial information, and treatment information. The entity notified HHS, affected individuals, media, and provided substitute notice; remediation included additional technical safeguards and staff retraining on email security.
- 🦬Montana State AGas victim2020-12-16
MEDNAX Services, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2020-12-16. The breach occurred from 6/17/2020 to 6/22/2020. 1,671 Montana residents were affected.
- 🦫Oregon State AGas victim2020-12-16
MEDNAX Services, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2020-12-16. The breach occurred during 6/17/2020 - 6/22/2020. The breach was discovered on 6/19/2020. 2,411 individuals were affected. Notice was sent on 12/16/202012/17/202012/18/2020.
- 🌲Washington State AGas victim2020-12-16
MEDNAX Services, Inc., a health sector entity reported a phishing incident to the Washington Attorney General. The organization became aware of the incident on 2020-06-19 and filed notice on 2020-12-16. 29,861 Washington residents were affected. 180 days elapsed between awareness and notification. 2 days to identify the breach. 3 days to contain the breach.
- FLHHS OCRas victim2019-04-20
EmCare, Inc. (FL, Healthcare Provider) reported to HHS OCR on 2019-04-20 a Hacking/IT Incident affecting 31,236 individuals. Numerous employees fell victim to an email phishing scheme compromising PHI stored in email systems. Exposed data included names, addresses, dates of birth, driver's license numbers, Social Security numbers, treatment information, and financial data. EmCare implemented additional administrative/technical safeguards, retrained staff on phishing identification, and notified affected individuals, media, and posted substitute notice. OCR provided technical assistance and obtained assurances of corrective actions.