Intermountain Health
ent_7954b43548b0fba11377a0fc
Disclosures
7
State AG · HHS OCR · 6 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
28,628
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Intermountain Health
- Normalized
- intermountain health— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- intermountainhealthcare.org
Disclosure history (7)newest first
- New Hampshire State AGas victim2021-07-22
Intermountain Healthcare notified the NH AG of a third-party data incident involving its business associate, Elekta. Unauthorized access to PHI occurred between April 6-20, 2021. Data included names, scanned medical images, and potentially SSNs/DOB. 1 NH resident affected. Notice sent July 16, 2021.
- Maine State AGas victim2021-07-16
Intermountain Healthcare, acting as a business associate, reported an external hacking incident that occurred on April 6, 2021, and was discovered on May 17, 2021. The breach affected 2 Maine residents, compromising their names and driver's license or non-driver ID card numbers. Intermountain Healthcare provided written notification to the affected individuals on July 16, 2021, and offered one year of credit monitoring and identity restoration services through Experian.
- UTAHHHS OCRas victim2021-07-16
Intermountain Healthcare reported to HHS on 2021-07-16 a Hacking/IT Incident affecting 28,628 individuals. Breached information located on Electronic Medical Record, Network Server. A business associate experienced a ransomware attack affecting ePHI including names, SSNs, and medical images.
- Indiana State AGas victim2021-07-16
Intermountain Healthcare reported a data breach to the Indiana Attorney General. The breach occurred on 2021-04-06 and was reported on 2021-07-16. 3 Indiana residents were affected. 28,628 individuals affected in total.
- Massachusetts State AGas victim2021-07-16
Intermountain Healthcare reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-07-16. 8 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2021-07-16
Intermountain Healthcare notified Montana residents of a data security incident involving its third-party vendor, Elekta. Unauthorized access to PHI occurred between April 6 and April 20, 2021. Data included names, scanned medical images, and potentially SSNs/DOB. No evidence of misuse found. Credit monitoring offered.
- UTAHHHS OCRas victim2013-04-26
IHC Health Services, Inc. dba Intermountain Life Flight reported to HHS on 2013-04-26 a Unauthorized Access/Disclosure affecting 857 individuals. Breached information located on Other. An employee inadvertently uploaded documents containing PHI to an unsecured department website in October 2009.
Supply-chain cascadesreviewed and confirmed
- Intermountain Health’s filing is one of at least 3 in the Elekta supply-chain incident (2021).