The covered entity (CE), Oklahoma Department of Human Services, reported that it inadvertently issued client notice letters with a second, unrelated client’s name and address due to a software change, affecting 813 individuals. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE developed and deployed a solution that stopped incorrect information from being added to the notice letters provided to clients. OCR obtained assurances that the CE implemented the corrective action steps noted above.