The covered entity (CE), University of Miami, reported that an individual used the computer credentials of an employee to gain access to its network environment which contained the protected health information (PHI) of 973 individuals. The PHI involved included names, dates of birth, diagnoses, and other treatment information. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative, technical, and security safeguards.