On June 22, 2017, a digital camera with stored photographs of patients’ chart labels and photographs of patients’ skin conditions was stolen out of a physician’s vehicle which was parked outside the physician’s home. The stolen camera contained protected health information (PHI) created between February 15, 2017, and June 21, 2017, including 902 individuals’ demographic and clinical information. The physician reported the theft to law enforcement. The covered entity (CE) provided breach notification to HHS, affected individuals, and the media, posted substitute notice on its website, and established a call center to answer patients’ questions and public inquiries. Following the breach, the CE updated its policies and procedures for safeguarding PHI on mobile devices, requiring employees to install encryption software on all CE-approved cell phones and mobile devices and banning the removal of cameras and camera memory cards from the CE’s premises. The CE also trained workforce members on securely capturing and storing electronic PHI on mobile devices. In October 2018, the CE began a comprehensive enterprise wide risk analysis that continued into 2019. OCR obtained documented assura