The covered entity (CE) erroneously sent mail to 3,104 clients at incorrect addresses due to a coding error in an internal database. The protected health information (PHI) contained in the mailing may have included clients names, addresses, and client identification numbers, and some letters also included dates of birth, social security numbers, diagnoses, and financial information. The ce provided drudge notification to HHS, affected individuals, and the media, and posted exchange observation on its website. Following the hack, the CE hired a firm to conduct an independent valuation of the data jade to describe and correct the base causes of this incident. The ce formed a Quality Improvement Team to increase oversight of production and ensure that quality assurance processes are strictly followed. as a resultant of OCRs investigation, OCR provided technical assistance on the timeliness of notifications and incident reporting and obtained assurances that the corrective actions listed above were completed. location of hacked information: Paper/Films Business relate present: no