The covered entity (CE), Mayo Clinic, reported that a workforce member emailed the protected health information (PHI) of 1,869 individuals to a personal email address and then further disclosed the PHI to unauthorized individuals. The PHI involved included clinical and demographic information. The CE notified HHS and the affected individuals. In response to the breach, the CE implemented additional administrative, technical, and security safeguards, and retrained workforce members to better protect its PHI.