UTMalwareHealthcareHealthcareRansomwareData EncryptedRansom DemandedCustomer Data InvolvedData ExfiltratedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICCriticalResolved
Uintah Basin Healthcare
bd_eb01c57f3c007511 · schema v1 · pii pii-v1
Full breach record for Uintah Basin Healthcare →Uintah Basin Healthcare (UT) reported to HHS on 2023-05-10 a ransomware attack affecting 103,974 individuals. PHI stored on network servers was compromised, including names, addresses, dates of birth, Social Security numbers, diagnoses, lab results, medications, and health insurance information. The CE notified HHS, affected individuals, and the media, provided substitute notice, offered complimentary credit monitoring, and implemented additional safeguards including staff retraining.
HIPAA clock✓ HHS notified
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_415f1ac33d574165Montana State AGfiled 2023-05-09(1d gap)Candidate
- bd_793c4ab76a8e3c9dVermont State AGfiled 2023-05-09(1d gap)Candidate
- bd_56524b94f00dd018Maine State AGfiled 2023-05-12(2d gap)Verified
- bd_b04aa0771e10f15fOregon State AGfiled 2023-05-12(2d gap)Candidate
Source provenance
- Source URL
- https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 10, 2023
- Raw hash
- fda9831517a2fe2dab44b69315f411ee40cc7d41934922ea384818917cf2c401
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Uintah Basin Healthcarenorm: uintah basin healthcare
- Industry
- Health Care Services
Victim entity
- Name
- Uintah Basin Healthcarenorm: uintah basin healthcare
- Industry
- Health Care Services
- Industry
- Healthcaresource default
Incident
- Discovered
- Apr 7, 2023
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 103,974
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- HHS OCR notifiedmedia notifiedsubstitute notice provided
Compliance
- Compliance flags
- HHS notified
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status HIPAA Discovered: Apr 7, 2023→ Notified: not extracted— regulatory submission HHS notified
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.