On August 1, 2014, Madison Street Provider Network, the covered entity (CE), discovered that an employee’s unencrypted laptop computer was stolen from a locked car. The laptop contained emails containing patients’ names, dates of birth, telephone numbers, and clinical information. The CE determined that the beach affected 523 individuals. The CE provided breach notification to affected individuals, the media, and HHS. Following the breach, the CE encrypted all laptops, updated and revised its HIPAA policies, and counseled the responsible employee. OCR provided the CE with technical assistance regarding a security management process that accurately and thoroughly identifies and mitigates the risks posed to its receipt, maintenance, and transmission of electronic protected health information.