IHC Health Services
Disclosed Apr 26, 201313 years ago857 affectedConfirmed
IHC Health Services, Ind., dba Intermountain Life Flight, the covered entity (CE), reported that, in or around October 2009, an employee inadvertently uploaded documents containing protected health information (PHI) to a department’s externally managed and unsecured website, in violation of its corporate policy prohibiting such conduct. The CE indicated that the website was for department operation purposes and not intended to include PHI. The breach affected 857 individuals’ demographic information (including names, addresses, dates of birth, and/or social security numbers) and/or clinical information (including diagnoses). The CE provided timely breach notification to affected individuals, the media, and HHS, and providing substitute notice by posting the breach on its website. It also offered affected individuals credit monitoring for one year. Following the breach, the CE promptly disabled the website, verified secure data destruction, and conducted an internal investigation and incident response, including root cause analysis, corrective education, and risk-based action plan that encompassed the entire enterprise. The CE also terminated its relationship with its external vendo
What is known
| People affected | 857 (as reported to HHS) |
|---|---|
| Disclosed | Apr 26, 2013 |
| Attack | Insider |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| HHS OCR breach report (archive, resolved): IHC Health Services (Healthcare Provider, UT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| HHS archivetotal | Apr 26, 2013 | 857 |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.