Skip to content

Central Utah Clinic

Disclosed Aug 7, 201412 years ago31,677 affectedConfirmed

Official notice

On June 9, 2014, Revere Health, the covered entity (CE), discovered that cybercriminals had compromised one of its Internet-facing servers containing electronic protected health information (ePHI), affecting 31,677 patients. The compromised ePHI which included images, written imaging notes, and radiology reports dating 2010 and earlier, which contained identifying patient information – names, and/or dates of birth, and/or social security numbers, and/or addresses, and/or telephone numbers. The CE provided breach notification to the affected individuals, the media, and HHS. Following the breach, the CE took several corrective actions, including but not limited to: updating its inventory of ePHI, servers, databases, users, and applications; reducing vulnerabilities and blocking the affected server from the Internet; conducting penetration tests; drafting new security policies; implementing new response procedures; updating patch management procedures; upgrading the functionality in its firewalls, antivirus, and antimalware software; expanding its security team; and providing security and awareness training to its workforce. In the course of its review, OCR provided the CE with techni

What is known

People affected31,677 (as reported to HHS)
DisclosedAug 7, 2014
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
HHS OCR breach report (archive, resolved): Central Utah Clinic (Healthcare Provider, UT)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
HHS archivetotalAug 7, 201431,677

Other breaches at Central Utah Clinic

BreachAffected
Disclosed Aug 19, 2021Aug 19, 20215 years agoHacking12K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Central Utah Clinic

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.