Skip to content

Mayfield Clinic

Disclosed Apr 23, 201610 years ago23,341 affectedConfirmed

Official notice

An unauthorized person sent a fraudulent email with an attachment that triggered a download of a ransomware virus to 23,341 email addresses held by the covered entity’s (CE’s) business associate (BA) on its behalf. The protected health information (PHI) involved in the breach included email addresses. The CE sent an email notification to affected individuals on the day of the incident and sent another email notification two days later. The CE provided breach notification to HHS, affected individuals, and the media and also posted substitute notice on its web site. Following the breach, the CE assessed system controls, provided anti-scanning updates to its employees’ email, deleted the email addresses it maintained on its BA’s systems, and put a hold on the future electronic distribution of newsletters. OCR obtained written assurances that the CE implemented the corrective actions listed above.

What is known

People affected23,341 (as reported to HHS)
DisclosedApr 23, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mayfield Clinic (Healthcare Provider, OH)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalApr 23, 201623,341
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mayfield Clinic

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.