The MetroHealth System, the covered entity (CE), reported that an employee of its vendor included the protected health information (PHI) of 1,748 individuals in mailings to other individuals who requested their medical records. The PHI involved included names and treatment information. The CE notified HHS, affected individuals, and the media. In its mitigation efforts, the CE and its vendor implemented additional administrative safeguards to protect sensitive data.