Integrative Health of Utah, PLLC Data Breach
Integrative Health of Utah Data Theft Affects 600 Patients
What happened in the Integrative Health of Utah, PLLC data breach?
The Integrative Health of Utah, PLLC data breach was reported on April 3, 2023 and affected 600 individuals. The breach type was Theft involving Electronic Medical Record, Paper/Films. This breach occurred in Utah. Under HIPAA, affected patients must be notified within 60 days and may be entitled to credit monitoring services.
Integrative Health of Utah, PLLC Breach Details
Breach Overview
Integrative Health of Utah, PLLC, a healthcare provider based in Utah, experienced a data breach involving the theft of patient records on or before April 3, 2023, when the breach was reported to state authorities. The incident resulted in unauthorized access to both electronic medical records and physical paper/film documents containing protected health information (PHI) belonging to approximately 600 patients. This theft-based breach represents a significant compromise of patient privacy and confidentiality, requiring immediate notification and remediation efforts in accordance with HIPAA Breach Notification Rule requirements.
Company Response
Upon discovery of the theft, Integrative Health of Utah, PLLC initiated an investigation to determine the scope and nature of the breach. The organization submitted a breach notification report to the Utah state health authority on April 3, 2023, triggering the formal breach notification process. The entity was required to conduct a thorough risk assessment to determine whether the stolen information posed a reasonable risk of harm to affected individuals. Given the nature of the data involved—electronic medical records and physical documents—the organization likely determined that notification was warranted under HIPAA regulations, which mandate notification when there is a reasonable likelihood that PHI has been compromised.
Specific Details
Nature of the Theft
The breach involved the theft of both electronic medical records and paper/film documents, indicating a multi-format data compromise. This dual-format theft suggests either a physical theft of office materials combined with electronic access, or a situation where records were removed from the facility in tangible form. Theft-based breaches of this nature typically occur through unauthorized removal of materials by employees, contractors, or external actors who gain access to storage areas, filing systems, or unsecured workstations. The involvement of both electronic and physical records indicates potential gaps in access controls, document management procedures, and physical security measures.
The fact that paper and film records were included in the theft is particularly significant, as it suggests the breach may have involved physical access to patient file storage areas or imaging archives. This type of breach often indicates inadequate physical security controls, such as unlocked file cabinets, unsecured storage rooms, or insufficient monitoring of document handling procedures. Electronic medical record theft, conversely, may indicate compromised user credentials, inadequate system access controls, or unauthorized data export capabilities.
Organizational Context
Integrative Health of Utah, PLLC operates as a healthcare provider offering integrative and complementary medicine services within the state of Utah. The organization's focus on integrative health suggests a practice model that may combine conventional medical care with alternative or complementary therapies. As a PLLC (Professional Limited Liability Company), the organization operates as a private healthcare entity. The breach affected 600 individuals, indicating a mid-sized patient population, though the organization's total patient base may be substantially larger.
Patient Impact and Notifications
Number of People Affected
Approximately 600 patients had their protected health information compromised in this breach. This represents a significant portion of the organization's patient records and indicates a substantial operational security failure. All affected individuals were required to receive breach notification letters in accordance with HIPAA requirements, which mandate notification without unreasonable delay and no later than 60 calendar days after discovery of the breach.
Personal Information Involved
Given the nature of the breach involving electronic medical records and paper/film documents, the following categories of protected health information were likely exposed:
- Patient Demographics: Names, addresses, dates of birth, and contact information
- Medical History: Diagnoses, treatment plans, medical conditions, and clinical notes
- Treatment Records: Medication lists, dosages, prescriptions, and treatment dates
- Imaging Records: X-rays, scans, and other radiological films or digital imaging data
- Insurance Information: Health insurance policy numbers, group numbers, and coverage details
- Financial Information: Billing records, payment history, and account numbers
- Provider Notes: Physician observations, clinical assessments, and care coordination documentation
The exposure of medical records is particularly sensitive, as this information can be used for identity theft, insurance fraud, or to obtain unauthorized medical services. Additionally, the disclosure of medical conditions and treatment information represents a serious violation of patient privacy.
HIPAA Compliance and Industry Context
Under the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), covered entities must notify affected individuals of breaches of unsecured PHI. The rule defines a breach as the unauthorized acquisition, access, use, or disclosure of PHI that compromises the security or privacy of the information. Theft inherently meets this definition, as it represents unauthorized access and removal of protected information.
Theft-based breaches remain a significant concern in healthcare, accounting for a notable percentage of reported HIPAA breaches annually. According to breach reporting data, theft incidents often involve physical documents and can occur through employee misconduct, contractor negligence, or external criminal activity. The involvement of both electronic and paper records in this incident is consistent with patterns observed in healthcare theft cases, where perpetrators may target multiple data formats to maximize the value of stolen information.
The organization was required to conduct a risk assessment to determine whether notification was necessary. Under HIPAA guidance, a breach is presumed to pose a reasonable risk of harm unless the entity demonstrates through a risk assessment that there is a low probability that the PHI has been compromised. Given that the information was stolen—rather than merely lost—it is reasonable to assume that notification was deemed necessary, as theft inherently suggests intentional unauthorized access.
Affected patients should be aware that their medical information may be at risk for misuse, and they should monitor their healthcare accounts, insurance statements, and credit reports for suspicious activity. The organization should have provided guidance on credit monitoring, identity theft protection resources, and steps patients can take to protect themselves.
What Data Was Exposed
Risks to Patients
What to Do If You Were Affected by the Integrative Health of Utah, PLLC Breach
Monitor credit reports from all three major credit bureaus (Equifax, Experian, TransUnion) for unauthorized accounts or inquiries; consider placing a fraud alert or credit freeze
Review healthcare and insurance statements regularly for unauthorized charges, claims, or services; contact providers immediately if suspicious activity is detected
Change passwords for any online healthcare portals or patient accounts associated with Integrative Health of Utah and use strong, unique passwords
Consider enrolling in identity theft protection or credit monitoring services if offered by the organization; maintain awareness of phishing attempts and verify communications before providing additional information
Monitor Your Medical Records
Request copies to check for unauthorized changes
Check More Utah Breaches
Search all breaches reported in Utah