Lawmakers attempt to resolve statewide security breach with new regulations
SALT LAKE CITY — Lawmakers intend to further rectify a statewide data breach that left the personal information of up to 800,000 Utahns at risk earlier this year.
Names, birth dates and Social Security numbers of individuals that were inappropriately stored on a Utah Department of Technology Services server were exposed to hackers in early April, leading to an international criminal investigation and widespread local mitigation of potential damages, including for identity theft.
The majority of individuals impacted by the breach were recipients of state Medicaid programs, including the Children's Health Insurance Program, however, a portion of the names and individuals affected were not participants in state insurance programs.
"Most of the people who were breached had no idea that their private information had been accessed through the government databases, and I'd guess that most didn't know they'd given authorization for that to happen," Sen. Stuart Reid, R-Ogden, who is sponsoring the draft legislation, told the Health and Human Services interim committee Wednesday.
The bill would require providers to notify patients that patient information queries might be sent to and from government databases, including various private information. It also requires the state to properly protect any information, utilizing the best available practices within the security industry. It would convene a security council of sorts to review those practices on an annual basis, as well as employ an audit every two years to ensure such practices are adhered.
"More than anything, we need to let our citizens know that we're doing all that we can to protect their private information," Reid said. He was among those notified after the breach that his information might have been compromised and he believes at least some of the information that was hacked, never should have been on the state server in the first place.
Sen. Allen Christensen, R-Ogden, said patients are already bombarded with paperwork when visiting a doctor's office or hospital, but he was assured that the required notification would be added to existing Health Insurance Portability and Accountability Act requirements, in which a patient releases private information for insurance purposes.
David Gessel, with the Utah Hospital Association, said the notice "won't be much of an additional burden, but it is important to be clear" what patients will be signing.
The bill was passed out of the committee unanimously and will next be addressed in the upcoming open session of the Utah Legislature.
- New law helps Utah avoid marriage license...
- Utah bachelor lets sister set him up on 31...
- Mia Love paying back money spent on...
- FBI investigating fatal crash on Ute reservation
- $1M in heroin found in 'complex' hidden...
- SAGE scores, 2015: Top Utah schools in...
- BYU student health plan exemption expires
- Mom whose unbuckled child died was cited for...
- New law helps Utah avoid marriage... 83
- BYU student health plan exemption expires 54
- Popular Provo teacher imprisoned for... 47
- Mia Love paying back money spent on... 44
- Family of man killed by Spanish Fork... 34
- Does coal have a future in Utah? Should... 27
- Students see 'great growth' in second... 18
- About Utah: He walked around the lake... 15