The covered entity (CE), University of Florida Department of Epidemiology and Health Policy Research, mailed approximately 2,047 letters that contained an identifier on the address label that was an adaptation of either a child’s social security number or Medicaid identification number. The types of protected health information (PHI) involved in the breach included names, social security numbers, or Florida Medicaid numbers of the patients. The CE provided breach notification to HHS, affected individuals, and the media. Following the breach, the CE recalled the faulty files from the printing company and the medical survey company and updated its procedures and forms to ensure that data is handled in accordance with the Privacy Rule. The CE provided OCR with its 2011 Training Schedule for Research Coordinators at the Institute of Child Health Policy (ICHP). Included in this year-long training is a section dedicated to Regulatory Compliance, including the importance of HIPAA and data security. The CE also sanctioned the employees involved in the breach. OCR’s investigation resulted in the CE improving its physical safeguards and retraining employees.