On August 23, 2019, as a result of a phishing email sent to 679 Outlook users, an unauthorized user accessed the email account of a physician and five Outlook users who were forwarding their work email to external email accounts. The physician's email account contained protected health information (PHI), including the demographic and clinical information of approximately 5,368 patients. In response to the breach, the covered entity (CE) opened a “major incident,” broadcast an emergency technology message to all employee email addresses, temporarily disabled the employee’s Active Directory account, and deployed a script to pull back and delete the 679 phishing emails. In addition, the CE ensured that the physician immediately changed his or her account password and that the five employees that had forwarded the email to an external email address deleted the phishing email. The CE’s network blocked the phishing website address for all internal computer network traffic to the site. The CE provided breach notification to HHS and affected individuals and offered individuals credit monitoring and identity protection services. Following the incident, the CE trained clinical staff regardin