A Utah state privacy audit concluded that systemic weaknesses in access controls, records request handling, and incident response preparedness are putting sensitive child welfare and health information at risk within two Utah Department of Health and Human Services (DHHS) data repositories. The audit—stemming from a May 2025 probe and published by state auditor Tina Cannon—characterized the deficiencies as a critical failure to protect vulnerable populations, warning that inadequate safeguards around highly confidential data could enable misuse and long-term harm.
The review was initiated following a whistleblower complaint from a DHHS employee, according to the state auditor’s office. One of the repositories examined was the SAFE system used by the Division of Child and Family Services, with auditors citing inadequate access controls and insufficient incident response planning as key gaps requiring remediation to reduce exposure of sensitive records affecting millions of children and adults in Utah.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
Utah State Auditor Tina Cannon presented the audit findings to lawmakers, warning that sensitive child welfare and mental health data had been placed at risk by weak controls. State officials said there had been no hacking incidents, major data exposures, or confirmed misuse or inappropriate sharing involving the SAFE and eChart systems.
After completing the audit, the state auditor's office delayed public release of the findings to give DHHS time to address the identified weaknesses and reduce the risk that publicized gaps could be exploited. During this period, DHHS began implementing the audit's recommendations.
In May 2025, the audit found systemic deficiencies in the SAFE and eChart repositories, including overly broad access to sensitive records, weak role-based and least-privilege enforcement, insufficient monitoring, and incident-response gaps. Auditors reported that 1,222 SAFE users had broad viewing access without case-based restrictions or required justification, creating risk that a single compromised account could expose large volumes of data.
A whistleblower complaint prompted Utah state auditors to open a privacy audit into two Utah Department of Health and Human Services data repositories, the SAFE child welfare system and the Utah State Hospital's eChart system. The audit examined access controls, record handling, and incident response practices affecting sensitive child welfare and health data.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.