Mayo Clinic, the covered entity (CE), reported that an employee inadvertently submitted the protected health information (PHI) of 1,152 individuals to an academic journal; the data was then published via the Internet. The PHI involved included names, dates of birth, lab results, medical records numbers, gender, race, and treatment information. The CE notified HHS and affected individuals. In its mitigation efforts, the CE implemented additional administrative safeguards to better protect PHI. Staff were retrained.