Midland Memorial Hospital, the covered entity (CE), experienced an email phishing attack. The protected health information (PHI) affected by the attack included the names, account and medical record numbers, and treatment information of approximately 1,160 individuals. Upon discovering the breach, the CE took steps to immediately disable affected email accounts. The CE provided breach notification to HHS, affected individuals, and the media. As a result of the breach, the CE improved technical safeguards and retrained staff. OCR obtained assurances that the CE implemented the corrective actions listed.