Mayo Clinic Data Breach
Mayo Clinic Email Breach Affects 1,869 Patients in Minnesota
What happened in the Mayo Clinic data breach?
The Mayo Clinic data breach was reported on March 28, 2025 and affected 1,869 individuals. The breach type was Unauthorized Access/Disclosure involving Email. This breach occurred in Minnesota. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Mayo Clinic Breach Details
Mayo Clinic Unauthorized Email Access Incident
On March 28, 2025, Mayo Clinic, one of the nation's largest integrated healthcare systems, reported a breach involving unauthorized access to patient email communications. The incident resulted in the exposure of protected health information (PHI) for approximately 1,869 individuals. The breach was classified as an unauthorized access and disclosure event affecting email systems, indicating that an unauthorized party gained access to email accounts or email servers containing patient health information and communications.
Company Response
Mayo Clinic discovered the unauthorized access through its security monitoring systems and initiated a comprehensive investigation to determine the scope and nature of the breach. Upon discovery, the organization took immediate steps to secure affected email systems, prevent further unauthorized access, and preserve evidence for forensic analysis. The organization notified affected individuals in accordance with HIPAA Breach Notification Rule requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of a breach. Mayo Clinic also reported the incident to the U.S. Department of Health and Human Services Office for Civil Rights (OCR), as required by federal law for breaches affecting 500 or more residents of a state or jurisdiction.
Specific Details
The breach involved unauthorized access to email systems, which typically means that an attacker gained credentials or exploited a vulnerability to access email accounts or email servers. Email systems in healthcare organizations often contain highly sensitive patient communications, including clinical notes, test results, appointment information, and other protected health information. The fact that the breach was limited to email (rather than broader network systems) suggests a targeted attack on email infrastructure or compromised email credentials. Common vectors for email breaches include phishing attacks targeting staff credentials, exploitation of email server vulnerabilities, compromised administrative accounts, or insider threats. The investigation likely focused on determining how unauthorized access was obtained, what accounts were affected, and the duration of unauthorized access.
Organizational Context
Mayo Clinic is a world-renowned, nonprofit integrated healthcare system headquartered in Rochester, Minnesota, with major campuses in Minnesota, Florida, and Arizona, plus numerous satellite locations across the United States. The organization operates multiple hospitals, outpatient clinics, and specialized treatment centers, serving millions of patients annually. As a large healthcare provider with extensive electronic health record systems and email infrastructure, Mayo Clinic maintains significant volumes of patient data across multiple platforms. The organization's size and complexity mean that security incidents, while serious, are managed through established incident response protocols and dedicated cybersecurity teams.
Patient Impact and Notifications
Approximately 1,869 individuals were affected by this breach, representing patients whose health information was accessible through compromised email systems. The affected individuals likely included patients with active or recent care relationships with Mayo Clinic facilities. Notification letters were sent to affected individuals informing them of the breach, the types of information potentially exposed, the steps Mayo Clinic took to secure systems, and recommended actions for protecting their personal information. The notification process began following the organization's discovery and investigation of the incident, with the submission date of March 28, 2025, indicating when the breach was formally reported to regulatory authorities.
Industry Context and HIPAA Implications
Email-based breaches represent a significant category of healthcare data incidents, accounting for a substantial portion of reported HIPAA violations. The HIPAA Security Rule requires covered entities like Mayo Clinic to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). These safeguards include access controls, encryption, audit controls, and integrity controls. Email breaches often result from gaps in these safeguards, such as inadequate access controls, insufficient encryption of email in transit or at rest, or inadequate employee training on phishing and credential security. The 1,869 affected individuals in this incident falls within the medium-impact range for healthcare breaches, though the sensitivity of information in email communications elevates the risk profile. Similar email-based breaches have affected numerous healthcare organizations, making this a recurring vulnerability in the healthcare sector. Organizations are increasingly implementing multi-factor authentication, advanced email filtering, and encryption technologies to mitigate email-based breach risks.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Mayo Clinic Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze to prevent unauthorized credit applications
Review healthcare bills and explanation of benefits (EOB) statements carefully for unauthorized services or claims; contact your insurance provider and healthcare providers immediately if you identify suspicious activity
Change passwords for all healthcare-related accounts, email accounts, and financial accounts, using strong, unique passwords; enable multi-factor authentication where available
Monitor financial accounts and bank statements regularly for unauthorized transactions; consider placing alerts on accounts and reviewing credit card statements monthly for fraudulent charges
Be vigilant against phishing emails and suspicious communications claiming to be from healthcare providers or financial institutions; do not click links or download attachments from unsolicited emails, and verify requests by contacting organizations directly using known phone numbers
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Minnesota Breaches
Search all breaches reported in Minnesota
Technical Notes
Mayo Clinic Has 3 Reported Breaches
This organization has been involved in multiple reported data breaches.
- 2024-06-05—120,000 affected(Hacking/IT Incident)
- 2023-11-03—1,152 affected(Unauthorized Access/Disclosure)