Boston Medical Center, the covered entity (CE), engaged MDF Transcription, a business associate (BA), to provide transcription services for certain physicians. The BA subcontracted with Wave Technologies (Wave) to provide a website where transcribed notes could be reviewed by physicians of the CE. Wave contracted with Pair Networks (Pair) to provide a File Transfer Protocol (FTP) site to host the notes. On March 4, 2014, the CE discovered that the protected health information (PHI) of about 15,265 individuals was not password protected and could potentially be subject to unauthorized access. The PHI involved in the breach included names, addresses, dates of birth, and clinical information. The CE provided timely breach notification to affected individuals, the media, and HHS. As a result of OCR’s investigation, the CE contacted the BA and had the settings on the FTP site changed so that only individuals with usernames and passwords would be able to access the CE’s data. After the BA provided confirmation to the CE that the site had been reconfigured by Pair, the CE terminated its relationship with the BA. In addition, the CE created and implemented additional policies and procedure