A nurse practitioner (“NP”) of the covered entity (CE), University Urology, left the practice to start her own clinic. An administrative assistant of the CE provided the NP with lists of patient information in June 2013 and January 2014 that contained the names, addresses, gender, age, and first and last dates of service for 1,144 individuals. The CE provided breach notification to HHS, affected individuals, and the media. In response to the breach, the CE terminated the administrative assistant’s employment and sent a “cease and desist” letter to the NP. The CE also ensured that the lists were destroyed. Finally, the CE reviewed and revised its policies and re-trained its workforce. OCR obtained assurances that the CE implemented the corrective actions listed above.