The covered entity (CE), Northern Inyo Healthcare District, reported that its business associate (BA) experienced a ransomware incident that affected the protected health information (PHI) of 1,305 individuals. The PHI involved included names, dates of birth, addresses, drivers’ license and Social Security numbers, diagnoses, claims and financial information, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the BA implemented additional administrative and new technical safeguards.