MetroPlus Health Plan, Inc., the covered entity (CE), reported a breach of PHI when an employee emailed Excel spreadsheets to her own and a family member’s personal email addresses. The PHI contained the electronic protected health information (ePHI) of 15,212 members which included demographic information, limited medical information, and social security numbers. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE sanctioned the employee, ensured that the ePHI was deleted from the personal email addresses and the device used by the employee’s family member, and reminded all workforce members not to use personal email accounts to conduct the CE’s business. The CE also documented the impermissible disclosure of its members’ ePHI for accounting of disclosure purposes. As a result of OCR’s investigation, extensive technical assistance was provided, and the CE is expected to perform a thorough and accurate enterprise wide risk analysis and establish a risk management plan, to regularly review records of information system activity and implement security measures to guard against unauthorized access to ePHI transmitted over an el