Molina Healthcare, Inc., the covered entity (CE), made an error when it prepared mailing lists for its business associate (BA), Merrill Communications, LLC, to use when it sent letters to Molina beneficiaries from October 13, 2017 through October 23, 2017. As a result of the error, when the BA sent the letters they were delivered to an incorrect beneficiary. The breach affected 1,380 individuals and the types of protected health information (PHI) listed in the letters included beneficiaries’ names, member identification numbers, dates of service, and the name of the beneficiaries’ physicians. The CE sent timely breach notification to HHS, the affected individuals, and the media. It also offered affected individuals 24 months of free identity theft protection. To mitigate the breach, the CE conducted an outreach campaign to collect copies of the misdirected mail and sanctioned and retrained the responsible employees. OCR obtained assurances that the CE implemented the corrective actions listed above.