On November 17, 2016, after receiving information from law enforcement, the covered entity (CE) determined that its business associate (BA), Medstreaming, experienced a cybersecurity incident impacting 5,454 records of vascular and thoracic patients seen at the CE between 2012 and 2015. The data may have contained demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. Both the CE and the BA hired system forensic teams to look for exfiltration of data and evidence of inappropriate access to the system. The CE determined that the files contained PHI from other sources, suggesting that the breach came from an outside vendor. Despite this information, the CE rebuilt its Medstreaming platform, engaged a cybersecurity forensics firm to perform complete network compromise assessment, and improved technical safeguards, including monitoring the internet-facing cybersecurity posture of high-risk third party service providers and installing tools to block malware callback activity. OCR reviewed a copy of the BA Agreement, the notification of the breach to the affected individuals, as well as the security measures implemented to a