For a period of approximately 24 hours on July 25 and 26, 2017, an unauthorized individual was able to access an email account belonging to an employee of the covered entity, Florida Healthy Kids Corporation, via a successful phishing attack. The employee received the email on July 25, 2017, correctly identified it as suspicious, and contacted the CE’s information technology (IT) department. Following the IT department’s instructions, the employee opened an attachment to the email and entered her username and password, allowing the phishing program to access her email account. The CE determined that approximately 2,000 individuals were affected, and that the protected health information (PHI) involved included names, addresses, email addresses, dates of birth, phone numbers, social security numbers, member account numbers, immigration cards, health bills, medical claims information, and income verification documents. In response to this incident and OCR’s investigation, the CE conducted a complete review of its IT systems, and implemented additional security measures including improved auditing procedures and two-factor identification. The CE provided additional training related to