- State
- UT
- Covered entity type
- Business Associate
- Individuals affected
- 780,000
- Business associate present
- Yes
- Type of breach
- Hacking/IT Incident
- Location of breached information
- Network Server
- First seen by InfoSec Signals
- 9/23/2026
- Last seen in OCR export
- 9/23/2026
OCR description
OCR opened an investigation of the covered entity (CE), Utah Department of Health, after it reported that a hacker had gained access to the network server of it business associate (BA), Utah Department of Technology Services (DTS). During the cyberattack, the hacker copied the unencrypted electronic protected health information (ePHI) of approximately 780,000 individuals to an internet protocol address in Romania. The ePHI involved in the breach included names, addresses, birth dates, social security numbers, physicians’ names, and procedure codes designed for billing purposes. The CE provided breach notification to HHS, affected individuals, and the media, and provided free credit monitoring to affected individuals. Following the breach, the CE entered into a BA agreement with DTS. It also improved safeguards by developing an incident response plan, improving its password management process, strengthening its security practices to include encryption and improved firewalls, and completing a new risk analysis and risk management plan. OCR obtained assurances that the CE implemented the corrective actions noted above.
Change history
- 9/23/2026Added to OCR's archive list
Source: HHS OCR Breach Portal, U.S. Department of Health and Human Services, Office for Civil Rights about this source
Records are reproduced as published; entity names and figures are OCR's.