The covered entity (CE), Temple University Health System, reported that a software application used by its business associate (BA) exposed the protected health information (PHI) of 431,563 individuals. The PHI involved included names, dates of birth, addresses, diagnoses, and medications. The CE notified HHS, affected individuals, the media, and provided substitute notice. In response to the breach, the CE provided complimentary credit monitoring services and the CE and BA implemented additional administrative, technical, and security safeguards to better protect PHI.