The covered entity (CE), Andor Labs, reported that it was the subject of a ransomware attack that affected the protected health information (PHI) of 500 individuals. It was determined that this security incident did not constitute a breach because the CE’s PHI was not accessed, viewed, or disclosed. OCR provided the CE with technical assistance regarding the HIPAA Security Rule.