Clustered 12 filings across 7 jurisdictions · filing window Jan 7, 2022 → Feb 3, 2022. View entity profile → Other incidents for this victim →
incident inc_572e9b8ea61846cd · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
PII · Government ID
CA ME MT OR SC UT WA
HHS OCR · State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
12 filings across 7 jurisdictions · Jan 7, 2022 – Feb 3, 2022 · 2 milestones
Nov 2, 2021
When the intrusion reportedly occurred, per the linked filings
Nov 9, 2021
Reported by MAINE AG, WASHINGTON AG, CALIFORNIA AG, SOUTH CAROLINA AG, OREGON AG filings
Medical Review Institute of America reported to HHS on 2022-01-07 a Hacking/IT Incident affecting 172,420 individuals. Breached information located on Network Server. The business associate implemented additional administrative and technical safeguards and provided complimentary credit monitoring services.
Affected (this filing): 172,420
Medical Review Institute of America reported to HHS on 2022-01-20 a Hacking/IT Incident affecting 2406 individuals. Breached information located on Network Server. The business associate implemented additional administrative and technical safeguards and provided complimentary credit monitoring services to affected individuals.
Affected (this filing): 2,406
Medical Review Institute of America reported a data breach to the Maine Attorney General, indicating that an external system breach (hacking) occurred on November 2, 2021. The breach was discovered on November 9, 2021, and affected 271 Maine residents. The compromised information includes names and Social Security Numbers. The company is offering 12 months of credit monitoring and identity theft protection services through Kroll.
Affected (this filing): 271
Medical Review Institute of America (MRIoA) disclosed a cyber-attack on November 9, 2021, involving unauthorized access to protected health information (PHI) and personal data (SSN, DOB, demographics). MRIoA engaged forensic experts, notified the FBI, and confirmed deletion of exfiltrated data. Remediation included enhanced authentication, new servers, and Kroll-provided identity monitoring for affected individuals.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Medical Review Institute of America, a healthcare organization, reported an external system breach (hacking) that occurred on November 2, 2021, and was discovered on November 9, 2021. The breach affected 194 Maine residents, compromising their names and Social Security numbers. The company notified affected individuals on January 7, 2022, and offered 12 months of credit monitoring and identity theft protection services.
Affected (this filing): 194
Medical Review Institute of America, a health sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-11-09 and filed notice on 2022-01-07. 3,225 Washington residents were affected. 59 days elapsed between awareness and notification. 7 days to identify the breach. 0 days to contain the breach.
Affected (this filing): 3,225
Medical Review Institute of America (MRIoA) experienced a sophisticated cyber-attack resulting in the unauthorized acquisition of protected health information (PHI). The incident was discovered on November 9, 2021, with the breach occurring on November 2, 2021. Affected data included demographic information, social security numbers, clinical information, and financial information. MRIoA engaged forensic experts, notified the FBI, and confirmed the deletion of the stolen data. The company implemented additional cybersecurity safeguards and offered one year of identity monitoring to affected individuals.
Medical Review Institute of America reported a data breach to the Montana Attorney General. The breach was reported on 2022-01-07. The breach occurred from 11/9/2021 to 11/16/2021. 404 Montana residents were affected.
Affected (this filing): 404
Medical Review Institute of America (MRIoA) reported a data breach to the Oregon Attorney General. The breach was reported on 2022-01-10. The breach occurred during 11/2/2021 - 11/9/2021. The breach was discovered on 11/9/2021. Notice was sent on 1/7/2022.
Medical Review Institute of America (MRIoA) disclosed a cyber-attack discovered on November 9, 2021, involving unauthorized access to protected health information (PHI) and personal data (SSN, DOB, demographics). MRIoA engaged forensic experts and the FBI, retrieved exfiltrated data, and confirmed its deletion. Affected individuals received one year of credit monitoring via Kroll. Remediation included enhanced authentication, new servers, and policy updates. No evidence of misuse was found at the time of notification.
Medical Review Institute of America reported an external system breach (hacking) occurring on November 2, 2021, discovered on November 9, 2021. The incident compromised the names and Social Security Numbers of approximately 157,885 individuals, including 269 Maine residents. The entity notified affected individuals in writing on January 20, 2022, and provided 12 months of credit monitoring and identity theft protection services.
Affected (this filing): 157,885
Medical Review Institute of America (MRIoA) disclosed a cyber-attack discovered on November 9, 2021, involving unauthorized access to protected health information (PHI) including names, SSNs, medical history, and insurance details. The breach occurred on November 2, 2021. MRIoA engaged forensic experts, notified the FBI, and deleted the stolen data. Affected individuals were offered one year of identity monitoring via Kroll.