Skip to content

Mayo Clinic

Disclosed Nov 3, 20232 years ago1,152 affectedConfirmed

Official notice

Mayo Clinic, the covered entity (CE), reported that an employee inadvertently submitted the protected health information (PHI) of 1,152 individuals to an academic journal; the data was then published via the Internet. The PHI involved included names, dates of birth, lab results, medical records numbers, gender, race, and treatment information. The CE notified HHS and affected individuals. In its mitigation efforts, the CE implemented additional administrative safeguards to better protect PHI. Staff were retrained.

What is known

People affected1,152 (as reported to HHS)
DisclosedNov 3, 2023
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mayo Clinic (Healthcare Provider, MN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalNov 3, 20231,152

Other breaches at Mayo Clinic

BreachAffected
Disclosed Mar 28, 2025Mar 28, 20251 year agoInsider1,869
Disclosed Oct 5, 2020Oct 5, 20205 years agoInsider1,614
Disclosed Mar 22, 2019Mar 22, 20197 years agoInsider1,902
Disclosed Sep 8, 2010Sep 8, 201016 years agoLost or stolen device1,740
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mayo Clinic

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.