The covered entity’s (CE) business associate (BA), Command Marketing Innovations, discovered a printing error that caused certain members and healthcare professionals to receive Explanation of Benefits (EOB) statements and Explanation of Payment (EOP) statements that included protected health information (PHI) information intended for a different member or health care professional. The breach impacted 55,715 members and the PHI included names, identification numbers, claim numbers, dates of services, descriptions of service, service codes, or provider/facility names. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE improved quality control procedures for mailings performed by the BA, added contractual requirements that require the BA to inform the CE in writing of all proposed production changes and obtain written approval from the CE before final production of printing jobs. OCR obtained assurances that the CE implemented the corrective actions listed.