An employee of the covered entity's (CE) business associate (BA), Island Peer Review Organization, lost an unencrypted and not password-protected portable computer drive (a "USB" drive) that contained 9,825 patients’ names, addresses, dates of birth, social security numbers, clinical information, diagnoses, conditions, and identification numbers (including member identification, Medicaid identification, subscriber identification, patient account number and patient control number). The CE, New Jersey Department of Human Services, provided breach notification to HHS, and the BA notified affected individuals and the media. Following the breach, the BA recovered all of the USB drives used by employees and retrained these employees on the BA’s security policies and the appropriate use of encryption on portable electronic media. As a result of OCR’s investigation and technical assistance, the BA retrained certain staff and implemented a policy requiring staff to use only portable media purchased by the BA's Information Systems Department. The BA installed technical safeguards on all computers so only approved portable devices are allowed access while any other types can be rendered as “r