A business associate (BA), Business and Professional Exchange, that provided the covered entity (CE) with 24-hour telephone answering services, experienced a ransomware incident affecting their computer network servers. The breach involved the electronic protected health information (ePHI) of approximately 16,276 individuals, including demographic and clinical information. The CE provided breach notification to HHS, affected individuals, and the media. OCR reviewed the BA agreement between the BA and CE and it appears to comply with the requirements of the HIPAA Rules. Following this incident, the parties no longer have a business relationship.