Skip to content

Mayo Clinic

Disclosed Mar 28, 20251 year ago1,869 affectedConfirmed

Official notice

The covered entity (CE), Mayo Clinic, reported that a workforce member emailed the protected health information (PHI) of 1,869 individuals to a personal email address and then further disclosed the PHI to unauthorized individuals. The PHI involved included clinical and demographic information. The CE notified HHS and the affected individuals. In response to the breach, the CE implemented additional administrative, technical, and security safeguards, and retrained workforce members to better protect its PHI.

What is known

People affected1,869 (as reported to HHS)
DisclosedMar 28, 2025
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Mayo Clinic (Healthcare Provider, MN)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalMar 28, 20251,869

Other breaches at Mayo Clinic

BreachAffected
Disclosed Nov 3, 2023Nov 3, 20232 years agoInsider1,152
Disclosed Oct 5, 2020Oct 5, 20205 years agoInsider1,614
Disclosed Mar 22, 2019Mar 22, 20197 years agoInsider1,902
Disclosed Sep 8, 2010Sep 8, 201016 years agoLost or stolen device1,740
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Mayo Clinic

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.