Mayo Clinic Health System- Red Wing
Disclosed Jul 13, 201511 years ago601 affectedConfirmed
On May 18, 2015, an access audit revealed that the covered entity's (CE) employee accessed patients’ electronic medical records beyond the scope of authorized access and assigned job responsibilities. The CE discovered that the unauthorized access dated back to 2009. The breach affected approximately 601 individuals and the types of protected health information (PHI) involved in the breach included patients' diagnoses and medical conditions. The CE provided breach notification to HHS, affected individuals, and the media. During OCR’s investigation, the CE retrained the revenue department in its Red Wing SE Minnesota Region on its privacy rules. OCR obtained written assurances that the CE implemented the corrective action steps listed above.
What is known
| People affected | 601 (as reported to HHS) |
|---|---|
| Disclosed | Jul 13, 2015 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): Mayo Clinic Health System- Red Wing (Healthcare Provider, MN)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Jul 13, 2015 | 601 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.