- State
- UT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 31,677
- Business associate present
- No
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
On June 9, 2014, Revere Health, the covered entity (CE), discovered that cybercriminals had compromised one of its Internet-facing servers containing electronic protected health information (ePHI), affecting 31,677 patients. The compromised ePHI which included images, written imaging notes, and radiology reports dating 2010 and earlier, which contained identifying patient information – names, and/or dates of birth, and/or social security numbers, and/or addresses, and/or telephone numbers. The CE provided breach notification to the affected individuals, the media, and HHS. Following the breach, the CE took several corrective actions, including but not limited to: updating its inventory of ePHI, servers, databases, users, and applications; reducing vulnerabilities and blocking the affected server from the Internet; conducting penetration tests; drafting new security policies; implementing new response procedures; updating patch management procedures; upgrading the functionality in its firewalls, antivirus, and antimalware software; expanding its security team; and providing security and awareness training to its workforce. In the course of its review, OCR provided the CE with technical assistance regarding necessary changes to its policies and procedures, and its security management process.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.