The covered entity (CE), Hospital Sisters Health System, reported that several employees were the subjects of an email phishing scheme that affected the protected health information (PHI) of 16,167 individuals. The PHI involved included names, Social Security numbers, addresses, dates of birth, diagnoses, medications, and other treatment information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and implemented additional administrative, technical, and security safeguards. Staff were retrained on email security.