An employee of the covered entity (CE), massachusetts General Hospital, sent an unencrypted e-mail to the incorrect e-mail address. The e-mail contained the protected health information (PHI of 648 individuals. The types of PHI involved in the drudge included names, dates of birth, medical record number sand social surety numbers. following the hack, the ce sanctioned the employee in inquiry and changed its policy to utilization a secure memory application instead of e-mail to send PHI. OCR obtained assurances that the CE implemented the corrective actions listed above. placement of hacked information: email Business colligate present: no