An audit by the Utah State Auditor found critical privacy and security weaknesses at the Utah Department of Health and Human Services (DHHS), following a whistleblower complaint alleging inadequate incident response procedures and insufficient monitoring to detect and manage privacy incidents. The review focused on two high-sensitivity systems—SAFE (Utah’s child welfare case management system, reported to contain ~6 million records tied to >2 million individuals) and eChart (a mental health records repository maintained by the Utah State Hospital)—and concluded that gaps in documentation, controls, and oversight increase the risk of unmitigated exposure of sensitive data, particularly children’s information.
Separately, British Columbia’s Office of the Information and Privacy Commissioner reported intentional “snooping” by healthcare staff into patient records following the Lapu Lapu Day festival tragedy, with 71 unauthorized access incidents affecting the medical records of 16 individuals and attributed to 35 employees across multiple health authorities (plus one physician-office assistant). In contrast, HIPAA Journal’s reminder about the March 1, 2026 deadline for reporting “small” (<500 individuals) healthcare breaches to HHS OCR is primarily compliance guidance rather than a specific incident, though it underscores regulatory expectations for timely breach notification and the risk of penalties and compliance investigations for late reporting.

See the actors and campaigns active against you right now.
7 events from the most recent confirmed update back to the earliest known activity.
Following the audit findings, Utah DHHS was reported to be implementing recommended improvements to address the identified privacy and security deficiencies. The changes were aimed at strengthening access controls, monitoring, and reporting mechanisms.
The Utah State Auditor found critical privacy and security weaknesses in DHHS systems, including overly broad access, poor monitoring, improper disclosures, and excessive data retention. Auditors said the issues could expose residents' health information but found no evidence that SAFE or eChart had been successfully hacked.
A whistleblower complaint alleging inadequate incident response and insufficient monitoring prompted the Office of the Utah State Auditor to examine the Utah Department of Health and Human Services. The review focused on the SAFE child welfare system and the eChart mental health records repository.
The Office of the Information and Privacy Commissioner for British Columbia disclosed that about half of the patients treated after the Lapu Lapu Day festival tragedy later had their privacy breached. The report said 71 snooping incidents affected 16 individuals and stressed that such access is illegal, unethical, and damaging to trust in healthcare providers.
By June 20, 2025, the reporting period for the notified snooping incidents had reached 71 incidents involving the records of 16 individuals. The breaches were attributed to 35 employees across health authorities and Providence Health Care, plus one assistant at a physician's office with access to Fraser Health systems.
Between April 30, 2025 and June 20, 2025, multiple British Columbia health organizations notified the Office of the Information and Privacy Commissioner of intentional, unauthorized employee access to patient records tied to the festival incident. The reports concerned patients who received care after the tragedy.
Following the April 26, 2025 tragedy at the Lapu Lapu Day festival in British Columbia, multiple individuals received medical treatment. These patients later became the subjects of privacy breaches involving their medical records.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.