The covered entity (CE), New Jersey Department of Human Services sent a file containing electronic protected health information (ePHI) to its business associate (BA) to generate and send out 1095B forms. In the course of preparing the file, the CE added individuals’ names and the last four digits of their social security numbers to the wrong 1095B forms, so that recipients of the mailing received ePHI for individuals who were not household members. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE ceased its responsibilities for mailing the 1095B forms for the New Jersey Department of Children and Families (DCF), Division of Child Protection and Permanency and changed procedures so that DCF will mail the 1095B forms from its own database. OCR obtained assurances that the CE implemented the corrective actions listed. Additionally, the CE is expected to conduct a risk analysis, implement a corresponding remediation plan, and ensure the implementation of policies and procedures relating to information system activity review, security incident response and reporting, access and audit controls, and creating/maintaining retrieva