Myriad Genetic Laboratories (MGL), the covered entity (CE), reported that a workforce member mistakenly emailed a spreadsheet containing protected health information (PHI) to a patient. The PHI involved included names, telephone numbers, medical record numbers, treatment information, and claims information. The breach affected 1,719 individuals. MGL notified all affected individuals and OCR. The covered entity sanctioned the workforce member responsible for the breach. It revised its policy and implemented changes to protect sensitive data when using email communications. It re-trained all workforce members on the updated policy. In addition, the covered entity provided documentation that it has a security awareness and training program in place for all workforce members.