- State
- UT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 42,372
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On December 17, 2015, the covered entity (CE), Alliance Health Networks, LLC., discovered that a test database containing protected health information (PHI) was accessible to the public via the Internet. The breach affected approximately 42,372 individuals, and their unsecured PHI included names, addresses, telephone numbers, email addresses, medications, and some clinical information. The CE provided breach notification to affected individuals, the media, and HHS. The CE also mitigated the effects of the breach by immediately securing the database, implementing monitoring of its test databases, performing weekly vulnerability scans of its systems, and updating its policies to ensure that production data is not used in test databases. In resolving the breach, OCR provided the CE with technical assistance regarding necessary changes to its policies and procedures, as well its risk management process.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.