OCR initiated an investigation after the covered entity (CE), Centura Health, reported that it experienced a phishing attack. Because a few of its employees inadvertently responded to the fraudulent email by clicking on a link and providing their usernames and passwords, these employees’ email accounts may have been accessible to the attacker(s). The CE detected and contained the incident because less than 5% of its employees received the phishing email. The compromised email accounts resulted in a breach of 12,286 individuals’ electronic protected health information (ePHI) in the form of demographic (names, addresses, dates of birth, telephone numbers, social security numbers, other identifiers), clinical (diagnoses, lab results, medications, other treatment) and/or financial (claims) information. The CE provided breach notification to HHS, affected individuals, and the media. The CE also notified the Federal Bureau of Investigation and offered free credit monitoring services to the individuals who had their social security number or financial information potentially compromised. Following the breach, the CE updated its risk management plan which included escalating in priority it