An employee of the covered entity (CE), Florida Department of Health, sent an unencrypted email with an attachment containing the electronic protected health information (ePHI) of 2,477 patients to four physicians who were the intended recipients of the email. The ePHI in the attachment included patients’ dates of birth, social security numbers, screening test results, and diagnoses. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE contacted the recipients of the emails and verified that the emails were deleted and that the ePHI was not further used or disclosed. The responsible workforce member submitted her resignation before CE’s investigation was completed. The CE also reviewed its privacy and security policies and procedures and retrained staff. OCR obtained and reviewed copies of the CE’s policies and procedures and documentation of staff training.