On June 9, 2014, Revere Health, the covered entity (CE), discovered that cybercriminals had compromised one of its Internet-facing servers containing electronic protected health information (ePHI), affecting 31,677 patients. The compromised ePHI which included images, written imaging notes, and radiology reports dating 2010 and earlier, which contained identifying patient information – names, and/or dates of birth, and/or social security numbers, and/or addresses, and/or telephone numbers. The CE provided breach notification to the affected individuals, the media, and HHS. Following the breach, the CE took several corrective actions, including but not limited to: updating its inventory of ePHI, servers, databases, users, and applications; reducing vulnerabilities and blocking the affected server from the Internet; conducting penetration tests; drafting new security policies; implementing new response procedures; updating patch management procedures; upgrading the functionality in its firewalls, antivirus, and antimalware software; expanding its security team; and providing security and awareness training to its workforce. In the course of its review, OCR provided the CE with techni