The covered entity (CE), Georgia Department of Human Services, reported that its business associate (BA) experienced a cyber-attack that affected the protected health information (PHI) of 15,938 individuals. The PHI involved included names, Social Security numbers, dates of birth, drivers’ license numbers, financial information, diagnoses, and other treatment information. The BA notified affected individuals, the media, and posted substitute notice on its website. The CE notified HHS. In its mitigation efforts, the BA implemented additional administrative and technical safeguards and retrained its staff. OCR provided technical assistance to the CE regarding the HIPAA Breach Notification Rule.