The covered entity (CE), University of Miami Health System, reported that on or around June 27, 2013, it learned from Iron Mountain, its business associate (BA), that 15 boxes containing patients’ protected health information (PHI) were lost during the transfer between its new and old storage/shredding vendors. The boxes contained a mix of billing and research records of 13,074 patients that included financial and clinical information. Following the breach, the CE provided breach notification to HHS, affected individuals, and the media and also posted substitute notice on its website. The CE offered credit monitoring and identity theft protection to all affected individuals. The CE and BA reviewed the BA’s processes for the transfer, pick up, and storage of records and worked together to revise procedures for safeguarding archived PHI. The CE required the BA to re-train all of its personnel who handle the CE’s data and re-trained its workforce on its HIPAA Privacy and Security policies and procedures. Additionally, the CE hired a new HIPAA Privacy Officer, revised procedures for retaining records in order to avoid sending records containing billing information to off-site storage,