Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack resulting in the unauthorized acquisition of protected health information (PHI). The incident was discovered on November 9, 2021, with the breach occurring on November 2, 2021. Affected data included demographic information, SSNs, clinical records, and financial/insurance details. MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of the stolen data. Remediation included system hardening, enhanced authentication, and one year of identity monitoring via Kroll.