Numerous employees of the CE responded to an email phishing attack which requested the employee’s email username and password to authenticate their accounts. As a result, a number of employee direct deposit paychecks were diverted without notification and any electronic protected health information (ePHI) stored on the affected email accounts was made accessible. The affected email accounts contained the combined ePHI of 8,311 individuals. The ePHI involved in the breach included patients’ demographic, clinical and health insurance information and in some cases, social security numbers. In response to the incident, the affected users changed their passwords and the CE adjusted web filters. The CE improved technical safeguards to prevent future phishing attacks of this nature and accelerated the time table for its existing phishing education campaign for all employees. The CE provided a year of free credit monitoring and identity theft protection services to affected individuals. OCR’s investigation confirmed that the appropriate notifications were made and that corrective actions steps were taken.