An employee was arrested on-site for suspicion of identity theft after using electronic protected health information (ePHI) obtained while employed by the covered entity (CE) to open a citation card account in another individuals name. The employee had a criminal chronicle which was not identified during the CEs hiring process. The ce provided hack notification to HHS, move individuals, and the media. It also cooperated with the subsequent law enforcement investigation. following the hack, the ce sanctioned the employee and terminated and replaced its vendor for background checks of potentiality employees. The ce also improved its physical security, enhanced technical safeguards for ePHI, formed a committee to formalize written policies for safeguarding ePHI, and enhanced staff training. OCR obtained assurances that the ce implemented the corrective actions noted above. Location of hacked information: Electronic Medical tape Business associate present: No