The covered entity (CE), the University of Mississippi Medical Center, discovered that data on a segregated network server had been encrypted by ransomware on May 7, 2017. After an internal investigation, it was determined that the server contained data from a previous electronic medical record which had last been used around May 2016. The breach affected the demographic, clinical, and health insurance information of 7,492 individuals. The CE provided breach notification to HHS, affected individuals, and the media, and on its website. At the time of the breach and investigation, the CE was under a Corrective Action Plan (CAP) with OCR and being monitored by OCR's Pacific Region. The CE took voluntarily corrective action in response to the breach and as required under the CAP, including substantially revising its security policies and the conducing an enterprise-wide risk analysis. At the time of this submission, the CE was working with an internal monitor to ensure compliance with the CAP provisions. OCR obtained assurances that the CE implemented the corrective actions listed above and performed its notification obligations.