On January 4, 2018, the covered entity (CE), ConnectiCare, learned that its business associate (BA), RR Donnelly, sent some of their subscribers the wrong identification card. This incident affected 1,834 individuals, exposing demographic and health plan information. OCR reviewed the CE's policies and procedures relevant to this breach and the BA agreement with RR Donnelly. The policies and the BA agreement appear to be in compliance with the Privacy Rule. The CE directed the BA to take actions to address the programming logic error which caused the breach, and the BE implemented additional coding logic on January 24, 2018, to prevent this type of error from occurring again. The CE provided OCR with assurances that individuals affected by this breach and the media were notified in accordance with the Breach Notification Rule.