The covered entity (CE), Maritz Holdings, Inc., reported that a workforce member inadvertently sent a document that contained the electronic protected health information (ePHI) of 1,298 individuals, to the wrong recipients. The ePHI involved included names, addresses, and dates of birth. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE strengthened its administrative and technical safeguards and retrained its staff. OCR provided technical assistance regarding the CE’s Security Rule obligations.