The covered entity (CE), Centers for Medicare & Medicaid Services, reported that a software application used by its business associate (BA) exposed the protected health information (PHI) of 2,342,357 individuals. The PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses, claims and health insurance information, and other treatment information. The CE notified HHS, the affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and the BA implemented additional administrative, technical, and security safeguards to better protect PHI.