On April 14, 2015, two unencrypted tablet computers, a smartphone, and a backpack containing paper files—were stolen from two company vehicles of the covered entity (CE), National Seating & Mobility, Inc. The breach involved the protected health information (PHI) of 9,627 individuals and included demographic, clinical and financial information. The CE provided breach notification to HHS, affected individuals, and the media and posted substitute notice on its website. In response to the breach, the CE revised its policies and procedures, encrypted its desktop, laptop and tablet computers and employed remote wiping and tracking technology. OCR obtained assurances that the CE implemented the corrective actions listed above.