On October 25, 2017, the Viral Hepatitis Clinic at University of Alabama at Birmingham, the covered entity (CE), lost two unencrypted portable computer drives (i.e., "thumb" drives) that were used to transfer data from scanning equipment to the CE’s secure network. The thumb drives contained the protected health information (PHI) of 652 individuals in a spreadsheet containing demographic and clinical information. The CE retrieved the thumb drives, but could not determine whether the PHI contained on the thumb drives had or had not been viewed. In response to this incident and OCR’s investigation, the CE staff responsible for the lost thumb drives were counselled and reprimanded. The CE provided breach notification to HHS, the affected individuals and the media. The CE also implemented a new procedure, eliminating the need to use thumb drives to transfer data to and from the scanning equipment. It developed a written policy regarding the new procedure, the use of portable devices, and the security of data within the clinic. All relevant staff participated in HIPAA re-training, and training on the new policy and procedure. OCR obtained assurances that the CE implemented the correctiv