Bronson Healthcare Group (BHG), the covered entity (CE), reported that it was the victim of a phishing attack involving an email phishing scheme. This breach affected 8,256 individuals. The PHI involved included names, dates of birth, Social Security numbers, medications prescribed, insurance information, diagnoses, and treatment information. BHG notified HHS, affected individuals, and the media. As a result of this breach, BHG implemented additional administrative, technical and security safeguards to further protect its PHI. As a result of OCR’s investigation BHG updated its policies and provided training to all employees on methods of identifying phishing and other types of fraudulent emails. OCR obtained assurances that BHG implemented the corrective actions noted above.