The covered entity (CE), UT Southwestern Medical Center, reported that an employee sent an email to its business associate (BA) without a business associate agreement (BAA) in place. This breach affected the electronic protected health information (ePHI) of approximately 3,640 individuals. The ePHI involved included names and email addresses. The CE notified HHS and affected individuals. In response to the breach, the CE strengthened its administrative safeguards and retrained its workforce members on the importance of having a BAA in place prior to disclosing ePHI. OCR obtained assurances that the CE implemented the corrective actions noted.