Several perpetrators falsely established themselves as doctors or other health care professionals and obtained 1,851 individuals’ protected health information (PHI) by accessing member identification numbers through an independent third party web-based provider portal available to legitimate doctors and health care professionals. The PHI included names, date of births, gendesr, member identification numbers, and in several cases mailing addresses for the covered entity's (CE) health plan members. The CE provided breach notification to HHS, affected individuals and the media. Following the breach, the CE requested that the third party web-based provider implement multi-factor authentication procedures for users who run eligibility and benefits inquiries, and required additional safeguard steps for out-of-network providers who use the third party web-based portal system. OCR obtained assurances that the CE implemented the corrective actions listed. As a result of OCR's investigation, the CE is expected to conduct a risk analysis that addresses all potential risk and vulnerabilities in the entire operation, implement a risk management plan and corresponding risk mitigation activities,