The covered entity (CE), James R. Etzkorn, M.D. (Etzkorn), reported that the contents of its server was encrypted in a ransomware attack. After this breach incident was reported, Etzkorn reported an additional breach incident in which protected health information (PHI) was inadvertently mailed to the wrong recipients. These breaches affected 6,845 individuals. OCR consolidated the investigations into the subject review. The PHI involved in both incidents included names, clinical information, claims information, and diagnostic codes. The practice implemented administrative, technical, and security safeguards. In addition, Etzkorn conducted a risk analysis and implemented a risk management plan. OCR obtained assurances that the CE implemented the corrective steps noted above.