Newkirk Products, Inc. (NY), a business associate issuing member healthcare ID cards, reported to HHS OCR on 2016-08-09 a Hacking/IT Incident affecting 3,466,120 individuals. Prior to its acquisition by a new parent company, unauthorized individuals accessed a network server containing ePHI of ~3.99M health plan members. Exposed data included names, addresses, plan/group/member IDs, dependent names, primary care provider, and in some cases Medicaid IDs, dates of birth, and premium invoice information. The former parent decommissioned the server; a new IT environment was established. OCR required a risk analysis, remediation plan, and updated HIPAA policies.