An employee of the covered entity (CE) sent a group email to current and former patients inviting them to a cancer awareness event and mistakenly failed to mask the recipients' email addresses. This breach affected the protected health information (PHI) of 1,782 individuals by exposing names and an implicit indication that they may have received cancer treatment. The CE recalled the email and immediately investigated the breach. The CE provided breach notification to HHS, affected patients, and the media, and posted substituted notice on its website. The CE established a call center to answer questions for its patients. The CE counseled the involved employee, and the employee’s supervisor reinforced to all department employees instructions regarding the use of group emails and the importance of keeping patients’ emails confidential. The CE reviewed and revised its privacy program in March 2015 and September 2015, which included guidelines for security of electronic PHI/email. In addition, the CE confirmed that it uses an encryption program to ensure the security and integrity of data. OCR obtained assurances that the CE implemented the corrective actions listed above.