The Office for Civil Rights within the U.S. Department of Health and Human Services (OCR) has taken its first enforcement action against a business associate. On June 30, 2016, OCR announced that it entered into a resolution agreement and corrective action plan with Catholic Health Care Services of the Archdiocese of Philadelphia (CHCS) to settle potential HIPAA violations stemming from the theft of an employee’s company-issued cell phone that contained the particularly sensitive protected health information (PHI) of 412 nursing home residents. CHCS is a nonprofit organization that, at the time of the theft, provided management and information technology services to six nursing homes in the Philadelphia region, in addition to its other services for the benefit of the elderly, developmentally disabled individuals, young adults aging out of foster care, and individuals living with HIV/AIDS. As part of the settlement, CHCS is required to pay a resolution amount of $650,000. This announcement comes nearly three years after OCR was vested with direct enforcement authority over business associates.