Back to the register

IHC Health Services, Inc. dba Intermountain Life Flight

ArchivedSubmitted 04/26/2013
State
UT
Covered entity type
Healthcare Provider
Individuals affected
857
Business associate present
No
Type of breach
Unauthorized Access/Disclosure
Location of breached information
Other
First seen by InfoSec Signals
9/23/2026
Last seen in OCR export
9/23/2026

OCR description

IHC Health Services, Ind., dba Intermountain Life Flight, the covered entity (CE), reported that, in or around October 2009, an employee inadvertently uploaded documents containing protected health information (PHI) to a department’s externally managed and unsecured website, in violation of its corporate policy prohibiting such conduct. The CE indicated that the website was for department operation purposes and not intended to include PHI. The breach affected 857 individuals’ demographic information (including names, addresses, dates of birth, and/or social security numbers) and/or clinical information (including diagnoses). The CE provided timely breach notification to affected individuals, the media, and HHS, and providing substitute notice by posting the breach on its website. It also offered affected individuals credit monitoring for one year. Following the breach, the CE promptly disabled the website, verified secure data destruction, and conducted an internal investigation and incident response, including root cause analysis, corrective education, and risk-based action plan that encompassed the entire enterprise. The CE also terminated its relationship with its external vendor. Additionally, the CE retrained workforce members, and assigned individuals, pursuant to its established policy and procedure, to oversee security responsibility for the department. It also implemented procedures to identify and remedy, as needed, information system resources such as externally managed servers or websites with the CE’s data. OCR obtained assurances that the CE implemented the corrective actions listed above.

Change history

  • 9/23/2026Added to OCR's archive list

Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source

Records are reproduced as published; entity names and figures are OCR's.

Your cookie choices
We use essential cookies to run this site, and, only with your consent, an advertising cookie from Google to measure whether our ads lead to sign-ups and subscriptions. See our for details.