Intermountain Healthcare
Disclosed Jul 16, 20215 years ago28,628 affectedConfirmed
The covered entity (CE), Intermountain Healthcare, reported that its business associate (BA) experienced a ransomware attack that affected the electronic protected health information (ePHI) of 28,628 individuals. The ePHI involved included names, medical images, Social Security numbers, health insurance information, dates of birth, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the BA strengthened its technical and security safeguards to better protect its ePHI. OCR provided technical assistance to the CE regarding its Breach Notification Rule obligations.
What is known
| People affected | 28,628 (as reported by the organization) |
|---|---|
| Disclosed | Jul 16, 2021 |
| Happened | Apr 6, 2021 |
| Attack | Hacking |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Indiana Attorney General 2021 data breach report: Intermountain Healthcarein.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Intermountain Healthcare (Healthcare Provider, UT)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| Indiana AGresidents of IN | Jul 16, 2021 | 3 |
| HHS archivetotal | Jul 16, 2021 | 28,628 |
History of this record
- 2026-09-25 · attack: unknown to hacking · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Intermountain Healthcare, reported that its business associate (BA) experienced a ransomware attack that affected the electronic protected health information (ePHI) of 28,628 individuals. The ePHI involved included · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.