The covered entity (CE), Beebe Physician Network, learned that a temporary contractor handling the electronic protected health information (ePHI) of 1,883 individuals had previously been arrested for identity theft. The ePHI included social security numbers, driver’s license numbers, and other demographic information. Although no inappropriate access was identified, the CE learned that the contractor had been convicted of 5 counts of identity theft in the state of Pennsylvania in 2009, while working in a physician practice. The CE provided substitute notice and provided breach notification to HHS and the media. The CE offered one year of free identity theft monitoring and insurance to affected individuals. Following this breach, the CE reviewed its policies and procedures, worked with electronic medical record vendors to enhance its reports mechanisms, and re-assessed its requirements for staffing agencies. As a result of OCR’s investigation, the CE revised its procedures regarding backgrounds checks for newly employed staff.