Grand River Medical Group
ent_b5cc91493f4e84105c13f6f4
Disclosures
4
HHS OCR · State AG · 4 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
37,858
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Grand River Medical Group
- Normalized
- grand river medical— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (4)newest first
- IOWAHHS OCRas victim2021-02-12
Grand River Medical Group (Iowa) reported to HHS on 2021-02-12 a Hacking/IT Incident (email phishing) affecting 37,423 individuals. An employee was the victim of a phishing attack that compromised PHI including names, addresses, Social Security numbers, dates of birth, claims information, medications, and other treatment information. No business associate was involved. The CE notified HHS, individuals, and media; offered credit monitoring; strengthened technical safeguards; and retrained staff on email security. OCR provided HIPAA Security Rule technical assistance.
- Maine State AGas victim2021-02-12
Healthcare provider Grand River Medical Group, P.C. experienced an external system breach between October 19 and October 22, 2020. The incident was discovered on October 22, 2020, with potential data compromise confirmed by a forensic firm on December 15, 2020. The breach affected 37,858 individuals, who were notified in February 2021. The company offered 12 months of identity protection services to those affected.
- Montana State AGas victim2021-02-08
Grand River Medical Group, P.C. notified patients of unauthorized access to an employee email account. Documents containing names, DOB, and visit types were potentially viewed. No SSN or financial data involved. Forensic analysis found no evidence of exfiltration. MFA implemented and credit monitoring offered.
- Indiana State AGas victim2021-02-08
Grand River Medical Group PC reported a data breach to the Indiana Attorney General. The breach occurred on 2020-10-19 and was reported on 2021-02-08. 20 Indiana residents were affected. 37,858 individuals affected in total.