A vendor, OneTouchPoint CCI, incorrectly printed and mailed 3,667 identification cards for the business associate (BA), DentaQuest of Florida. The types of protected health information (PHI) involved in the breach included names, identification numbers, and dates of coverage. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media. Following the incident, the CE re-programmed the software to compare names and addresses, and conducted quality assurance tests to ensure accuracy. The BA re-issued identification cards and provided self-addressed, stamped envelopes and requested that the members return the previously sent cards. OCR reviewed copies of the CE’s policies and procedures related to the incident.