The covered entity (CE), Mount Sinai Medical Center, reported that a provider’s personal unencrypted portable computer drive (a universal serial bus (USB) drive) was lost or stolen from the CE. The USB drive contained the protected health information (PHI) of 610 individuals and included names, dates of birth, medical record numbers, procedure logs, procedure dates, procedure information, and clinical information. The CE provided breach notification to HHS, the media, and the affected individuals. Following the breach, the CE sanctioned the provider, reminded all workforce members of its guidance and resources for encryption, and retrained all workforce members on HIPAA privacy and security. As a result of OCR’s investigation, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and implement workstation security. The CE is expected to update and clarify its policies for portable devices and device and media controls and review its HIPAA training content. The CE is also expected to implement a comprehensive policy and procedure for personally owned electronic devices to ensure that they are encrypted, tracked and monitored for encryption.