An unencrypted portable data drive was lost by a pharmacy resident of the Arnold Palmer Hospital, a part of the covered entity (CE). The drive contained the protected health information (PHI) of 586 individuals, including names, birth weights, gestational age, admission and discharge dates, medical record numbers, and some transfer dates. The missing drive also stored personal items, a research study proposal, and two spreadsheets containing limited information on 586 babies who were part of a study. The CE provided breach notification to HHS, the media, and to the parents of the affected individuals because they were all minors. Substitute notice was posted on the CE’s website. The CE updated its policies and procedures for its data loss prevention system and added controls. The CE retrained the resident involved in the loss of data and provided additional information to all employees and medical staff members regarding the use of portable data devices through education and published articles. OCR obtained assurances that the CE implemented the corrective actions listed above.