An unauthorized person sent a fraudulent email with an attachment that triggered a download of a ransomware virus to 23,341 email addresses held by Mayfield Clinic Inc's business associate (BA) on its behalf. The protected health information (PHI) involved in the breach included email addresses. The company sent an email notification to affected individuals on the day of the incident and sent another email notification two days later. The company provided breach notification to HHS, affected individuals, and the media and also posted substitute notice on its web site. Following the breach, the company assessed system controls, provided anti-scanning updates to its employees’ email, deleted the email addresses it maintained on its BA’s systems, and put a hold on the future electronic distribution of newsletters. OCR obtained written assurances that the company implemented the corrective actions.
Affected (this filing): 23,341