Skip to content

Utah Department of Technology Services

Disclosed Apr 11, 201214 years ago780,000 affectedConfirmed

Official notice

OCR opened an investigation of the covered entity (CE), Utah Department of Health, after it reported that a hacker had gained access to the network server of it business associate (BA), Utah Department of Technology Services (DTS). During the cyberattack, the hacker copied the unencrypted electronic protected health information (ePHI) of approximately 780,000 individuals to an internet protocol address in Romania. The ePHI involved in the breach included names, addresses, birth dates, social security numbers, physicians’ names, and procedure codes designed for billing purposes. The CE provided breach notification to HHS, affected individuals, and the media, and provided free credit monitoring to affected individuals. Following the breach, the CE entered into a BA agreement with DTS. It also improved safeguards by developing an incident response plan, improving its password management process, strengthening its security practices to include encryption and improved firewalls, and completing a new risk analysis and risk management plan. OCR obtained assurances that the CE implemented the corrective actions noted above.

What is known

People affected780,000 (as reported to HHS)
DisclosedApr 11, 2012
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
HHS archivetotalApr 11, 2012780,000
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (HHS archive), confirmed by HHS OCR. Record counts are as reported. Not legal advice.

Everything about Utah Department of Technology Services

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.