The covered entity (CE), Kaleida Health, reported that numerous employees were the victims of an email phishing scheme that affected the electronic protected health information (ePHI) of 744 individuals. The ePHI involved included names, medical record numbers, dates of birth, diagnoses, Social Security numbers, health insurance information, treatment information, and other clinical information. The CE notified HHS, affected individuals, the media, and provided substitute notice on its website. In response to the breach, the CE revised its policies and procedures to better protect its sensitive data and retrained it workforce members. OCR obtained assurances that the CE implemented the corrective actions noted.