The covered entity (CE), SEES Group, reported that several employees were the victims of an email phishing scheme that affected the electronic protected health information (ePHI) of 3,797 CE patients. The ePHI involved included names, addresses, drivers’ license numbers, Social Security numbers, and clinical and health insurance information. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE strengthened its technical safeguards and retrained its workforce on email security. OCR provided the CE with technical assistance regarding the HIPAA Breach Notification Rule.