The University of Utah
ent_5dcaa5f6b83b08ff7302e061
Disclosures
9
HHS OCR · State AG · 3 jurisdictions
Multi-filing incidents
—
no multi-filing incident in sample
Max affected reported
8,606
nationwide · HHS OCR UT
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- The University of Utah
- Normalized
- the university of utah— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- utah.edu
Disclosure history (9)newest first
- UTAHHHS OCRas victim2023-08-15
University of Utah Health (Health Plan, UT) reported to HHS OCR on 2023-08-15 a Hacking/IT Incident affecting 8,606 individuals. A software application used by a business associate exposed PHI including names, dates of birth, addresses, Social Security numbers, financial and claims information, and treatment information stored on a Network Server. The CE notified HHS, affected individuals, and media, and provided substitute notice and complimentary credit monitoring. Additional administrative, technical, and security safeguards were implemented.
- New Hampshire State AGas victim2020-10-23
The University of Utah notified the NH AG of a ransomware attack on CSBS servers. Intrusion began July 16, 2020; discovered July 19. Affected data included SSNs, credit card, and bank info. One NH resident notified on Oct 21, 2020. Credit monitoring offered.
- UTAHHHS OCRas victim2020-07-20
University of Utah reported to HHS on 2020-07-20 a Hacking/IT Incident affecting 6606 individuals. Breached information located on Email. Employees were victims of an email phishing attack affecting protected health information (PHI).
- Montana State AGas victim2020-06-26
University of Utah notified Montana residents that an unauthorized person accessed an employee email account starting April 6, 2020. The incident exposed names, medical record numbers, and limited clinical information. No SSNs were involved. The account was secured and an investigation launched.
- UTAHHHS OCRas victim2020-06-08
University of Utah reported to HHS on 2020-06-08 a Hacking/IT Incident (email phishing) affecting 1,909 individuals. Multiple employees were victims of an email phishing attack that compromised PHI. Breached information was located in Email. No business associate was involved. This case was consolidated into an existing HHS OCR compliance investigation.
- Montana State AGas victim2020-05-19
University of Utah notified affected individuals that an unauthorized person gained access to an employee's email account starting February 3, 2020. The incident exposed names, dates of birth, medical record numbers, and limited clinical information. The account was secured and a cybersecurity firm was engaged.
- UTAHHHS OCRas victim2020-04-03
University of Utah reported to HHS OCR on 2020-04-03 a Hacking/IT Incident (email phishing attack) affecting 5,096 individuals. Multiple employees were victims of a phishing attack that compromised PHI stored in email. This case was consolidated into an existing HHS OCR compliance investigation. No business associate was identified.
- UTAHHHS OCRas victim2020-03-21
University of Utah Health (covered entity) reported an email phishing incident in which multiple employees' email accounts were compromised, exposing PHI. The HHS OCR breach portal lists 3,670 individuals affected for this entry; the narrative description references 18,317 individuals — the discrepancy likely reflects multiple related submissions. Exposed PHI included names, birthdates, lab results, medications, and diagnoses. The CE notified HHS, affected individuals, and the media, and implemented additional administrative, technical, and security safeguards. No business associate was indicated.
- UTAHHHS OCRas victim2018-06-02
University of Utah Health (Moran Eye Center) reported to HHS on 2018-06-02 a Theft affecting 607 individuals. A laptop computer and an external hard drive were stolen on or about April 3, 2018. The stolen devices contained retinal scans, names, dates of birth, and medical record numbers. The CE identified the thief, reported to police, upgraded physical security, developed a facility security plan, and inventoried PHI-bearing devices. OCR obtained corrective action assurances.