Highmark, the covered entity (CE), reported that an employee mailed the protected health information (PHI) of 6,205 individuals to outdated addresses. The PHI involved included names, addresses, dates of birth, member identification number, diagnoses, medications, and other treatment and financial information. The CE notified HHS, impacted individuals, and the media. In its mitigation efforts, the CE implemented additional administrative and technical safeguards to better protect its sensitive data. Staff were retrained.