Back to the register
IHC Health Services, Inc. dba Intermountain Life Flight
ArchivedSubmitted 04/26/2013
- State
- UT
- Covered entity type
- Healthcare Provider
- Individuals affected
- 857
- Business associate present
- No
- Type of breach
- Unauthorized Access/Disclosure
- Location of breached information
- Other
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
IHC Health Services, Ind., dba Intermountain Life Flight, the covered entity (CE), reported that, in or around October 2009, an employee inadvertently uploaded documents containing protected health information (PHI) to a department’s externally managed and unsecured website, in violation of its corporate policy prohibiting such conduct. The CE indicated that the website was for department operation purposes and not intended to include PHI. The breach affected 857 individuals’ demographic information (including names, addresses, dates of birth, and/or social security numbers) and/or clinical information (including diagnoses). The CE provided timely breach notification to affected individuals, the media, and HHS, and providing substitute notice by posting the breach on its website. It also offered affected individuals credit monitoring for one year. Following the breach, the CE promptly disabled the website, verified secure data destruction, and conducted an internal investigation and incident response, including root cause analysis, corrective education, and risk-based action plan that encompassed the entire enterprise. The CE also terminated its relationship with its external vendor. Additionally, the CE retrained workforce members, and assigned individuals, pursuant to its established policy and procedure, to oversee security responsibility for the department. It also implemented procedures to identify and remedy, as needed, information system resources such as externally managed servers or websites with the CE’s data. OCR obtained assurances that the CE implemented the corrective actions listed above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.