OCR opened an investigation of covered entity Utah Department of Health after a hacker gained access to the network server of its business associate, Utah Department of Technology Services (DTS), and copied unencrypted ePHI of approximately 780,000 individuals to an IP address in Romania. Breached information was located on a Network Server and included names, addresses, birth dates, SSNs, physicians' names, and billing procedure codes. The CE notified HHS, individuals, and media, provided free credit monitoring, entered a BA agreement with DTS, and implemented encryption, improved firewalls, a new incident response plan, and a risk management plan. OCR obtained assurances of corrective actions.
Affected (this filing): 780,000