Amerigroup Iowa, Inc., a business associate (BA) for the covered entity (CE), Iowa Department of Public Health, erroneously mailed letters to 1,191 of its minor members which contained the incorrect parent or guardian’s name. The type of protected health information (PHI) included in the breach included demographic and clinical information. The BA provided breach notification to affected individuals on behalf of the CE. Upon discovery of the breach incident on January 29, 2019, the BA investigated and determined that the incident resulted from a human error. Based on the breach, the BA sanctioned and retrained the responsible employee, revised its procedure for generating a member mailing list, and trained all workforce member on its updated procedure. OCR obtained assurances that the CE/BA implemented the corrective actions listed above.