Utah Department of Health
bd_e35e54add8872289 · schema v1 · pii pii-v1
Full breach record for Utah Department of Health →OCR opened an investigation of covered entity Utah Department of Health after a hacker gained access to the network server of its business associate, Utah Department of Technology Services (DTS), and copied unencrypted ePHI of approximately 780,000 individuals to an IP address in Romania. Breached information was located on a Network Server and included names, addresses, birth dates, SSNs, physicians' names, and billing procedure codes. The CE notified HHS, individuals, and media, provided free credit monitoring, entered a BA agreement with DTS, and implemented encryption, improved firewalls, a new incident response plan, and a risk management plan. OCR obtained assurances of corrective actions.
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 11, 2012
- Raw hash
- d08e1806c28e955f48ee201cdc9f8a5246261502d13e4d20f4c26a74fd8d24d4
Source filing
Reporting entity
- Name
- Utah Department of Technology Servicesnorm: utah department of
Victim entity
- Name
- Utah Department of Healthnorm: utah department of health
- Industry
- Health Care Services
- Industry
- Healthcaresource defaultGovernmentllm
Incident
- Discovered
- Not extracted — the OCR public portal omits it
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 780,000
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1041 Exfiltration Over C2 ChannelT1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- OCR investigation openedOCR obtained assurances of corrective action implementation
- Third party
- via Utah Department of Technology Servicesbusiness associate
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- no discovery dateNo discovery date was extracted, so no notification clock can be evaluated.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: not extracted→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.