A physician affiliated with Midland Memorial Hospital, the covered entity (CE), allowed access to 1,468 individuals’ unsecured medical paper records at the physician’s foreclosed home for approximately one month while bank and property management staff prepared the property for re-sale. The types of protected health information (PHI) involved in the breach included patients’ names, addresses, dates of birth, social security numbers, diagnoses/conditions, medications, and other treatment information. The CE provided breach notification to the affected individuals, the media and HHS. Following the breach, the CE implemented a new safeguard policy specifically addressing the removal of PHI from the facility, and retrained workforce members. OCR obtained assurances that the CE implemented the corrective actions noted above.