The Missouri Department of Mental Health, the covered entity (CE), discovered that a former private contractor of its business associate (BA), had placed private client data in an unsecured cloud storage portal. The breach lasted from March 17, 2018, through August 31, 2018, and affected approximately 9,000 individuals. The CE notified all affected individuals, the media, and OCR. The CE mitigated the effects of the breach by confirming that the data had been removed from the cloud storage portal and obtained written verification from all parties involved in identifying the breach that they had either destroyed the data, securely returned the data, or that they are securely retaining the data for chain of custody purposes. During the investigation, OCR provided the CE with technical assistance regarding the risk analysis and risk management provisions of the Security Rule.