Baptist Health Louisville, the covered entity (CE), reported that two of its employees had been victims of a phishing incident on two separate days, exposing the protected health information (PHI), including names, dates of birth, addresses, social security numbers, and clinical information, of 880 individuals. The CE provided timely breach notification to HHS, affected individuals and the media. At the time of the breach and subsequently, the CE trained its employees on its HIPAA policies and procedures including the reporting of suspicious emails. In response to the breach, the CE specifically retrained the employees involved in the phishing incidents on identifying and reporting potential phishing emails. OCR reviewed the CE's HIPAA policies and procedures during the investigation and obtained assurances that the CE implemented the corrective actions listed above.