The covered entity (CE), the New York State Office of Mental Health, reported that unauthorized individuals accessed protected health information (PHI) due to a system administrator’s incomplete installation of a web content management platform. The breach affected 21,880 individuals, and the types of electronic protected health information (ePHI) involved included demographic and clinical information. The CE provided breach notification to HHS, the media, and the affected individuals (including the offer of one year of identity restoration services at no cost to the affected individuals), and posted notice to its website. Following the breach, the CE conducted a forensic review, disconnected the applicable computer servers from its network and ensured there were no other internet servers vulnerable to attack. The CE increased technical, physical and administrative safeguards to enhance network security monitoring and sanctioned its workforce member in connection with the breach incident. During the investigation, OCR obtained assurances that the CE implemented the corrective actions listed above. Additionally, the CE is expected to conduct a risk analysis and implement a correspon