Utah Department of Health
bd_e35e54add8872289 · schema v1 · pii pii-v1
Full breach record for Utah Department of Health →OCR opened an investigation of covered entity Utah Department of Health after a hacker gained access to the network server of its business associate, Utah Department of Technology Services (DTS), and copied unencrypted ePHI of approximately 780,000 individuals to an IP address in Romania. Breached information was located on a Network Server and included names, addresses, birth dates, SSNs, physicians' names, and billing procedure codes. The CE notified HHS, individuals, and media, provided free credit monitoring, entered a BA agreement with DTS, and implemented encryption, improved firewalls, a new incident response plan, and a risk management plan. OCR obtained assurances of corrective actions.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Apr 11, 2012
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.