FirstHR

Employee Identity Theft: An Employer’s Guide

Employee identity theft for employers: identity fraud at the hiring stage, your liability for staff data, the controls that stop it, and ID theft benefits.

Nick Anisimov

Nick Anisimov

FirstHR Founder

Core HR
16 min

Employee Identity Theft

Three different problems wearing the same name, and what an employer actually owes in each one

An employee once forwarded me a letter from the IRS saying that wages had been reported under his Social Security number by a company in a state he had never worked in. He was not asking me to fix it. He was asking whether it had come from us.

I could not answer that with any confidence, and the discomfort of not being able to answer is what sent me down this whole topic. It turned out that his problem and my problem were two different problems that happen to share a name, and that a third one was sitting in my hiring process where I had never thought to look.

This guide covers all three: someone working under an employee's number, someone using a stolen identity to get hired by you, and staff data walking out of your own records. It covers what you owe in each case, the controls that prevent most of it, and where identity protection fits as a benefit. Collecting sensitive employee data once and keeping it behind role-based permissions is a large part of what I built FirstHR to do. This is general information rather than legal advice.

TL;DR
Employee identity theft covers three separate problems: a candidate hired under a stolen identity, an employee whose Social Security number is being used for work elsewhere, and staff records stolen from your own systems. Only the third creates direct legal exposure for you, and all three have controls that cost almost nothing.

What Employee Identity Theft Means for an Employer

Employee identity theft is the misuse of a worker's personal identifying information in a way that touches employment. For an employer it arrives from three directions, and the reason most small companies have no plan for it is that the three get discussed as if they were one thing.

Definition
Employee Identity Theft
The misuse of an employee's or applicant's personal identifying information in an employment context. It covers employment-related identity theft, where a third party works and earns wages under someone else's Social Security number; identity fraud at hire, where an applicant is engaged under an identity that is not theirs; and the compromise of employee records held by an employer, where names, dates of birth, Social Security numbers and bank details are exposed and then used to open accounts or file fraudulent tax returns.
Someone works under your employee’s identity
Who does itA stranger, usually in another state
What happensWages get reported to the IRS and the Social Security Administration under your employee’s name and number. Your employee finds out from a notice, not from you.
Your roleYou are a bystander with useful records. Your job is to help them prove what they did and did not earn.
Someone uses a stolen identity to get hired by you
Who does itAn applicant who is not the person on the documents
What happensThe identity clears your paperwork because the identity is real. The human being doing the job is somebody else, and often somewhere else.
Your roleYou are the target. Payroll goes out, systems get access, and unwinding it later is expensive.
Employee data is stolen out of your records
Who does itA phishing email, a lost laptop, a vendor incident, a former employee with live access
What happensYour files hold the complete kit: legal name, date of birth, home address, Social Security number, bank details and often a scanned ID.
Your roleYou are the responsible party. This is the direction that produces notification duties and lawsuits.

Keeping them separate matters because the correct response differs completely. In the first you are a helper with useful records. In the second you are the victim of a fraud that your hiring process was supposed to catch. In the third you are the one who has to send the letter.

How It Reaches a Small Business

It reaches you through the file you are legally required to build. Onboarding a single employee collects the exact combination a criminal needs: legal name, date of birth, home address, Social Security number, bank account details, and frequently a scanned copy of a passport or driver license.

No other document set in a small company is worth as much. A customer list is worth something to a competitor. An employee record is worth money to anybody, immediately, without any knowledge of your industry, which is why the HR folder is a target out of proportion to the size of the business holding it.

The Volume Behind the Problem
The Federal Trade Commission received more than 1.1 million reports of identity theft through IdentityTheft.gov in 2024, and consumers reported losing more than $12.5 billion to fraud that year, a 25 percent increase over the prior year, per the FTC release of March 10, 2025. Those are consumer reports rather than employer incidents, which is precisely the point: the people in those numbers are somebody's employees, and a share of the underlying data came out of employment records.

Size offers no protection here, and in one respect it makes things worse. A company of twenty people typically has one person who does payroll, benefits and IT access, no separation between those roles, and no second pair of eyes on a request that looks routine.

3
Distinct problems the phrase covers, each with a different response
1
Onboarding packet holds every element needed to impersonate someone
0
Cost of the two controls that close the most common routes

When Someone Else Works Under Your Employee's Number

Employment-related identity theft means someone else is earning wages under your employee's Social Security number, and the employee usually learns about it from a government notice rather than from any employer. The IRS flags it with a CP01E notice, which says the number may have been used by another person for employment purposes.

The IRS is explicit that a CP01E carries no known impact on the person's tax account. It places an identity theft indicator on the account, monitors it, and recommends filing on time, getting an Identity Protection PIN, reviewing the Social Security earnings record, and considering a lock on the number. The IRS guidance on employment-related identity theft lists the other ways it surfaces: a CP2000 or CP2057 notice about income the person did not earn, or a Form W-2 arriving from an unfamiliar employer.

Your side of this is quieter and still useful. You hold the wage records that prove what the employee actually earned with you, the employment dates, and the work location. Producing those quickly, in writing, is most of what they need from you.

The Letter That No Longer Arrives
Employers used to be told about name and number mismatches directly. The Social Security Administration mailed Employer Correction Request notices, widely known as no-match letters, and discontinued them in April 2021 in favor of the correction tools inside its Business Services Online portal. The practical effect for a small employer is that nobody writes to you any more. A mismatch surfaces when a wage report is filed, and only if somebody looks. Treat one as a data problem first, because a marriage, a hyphenated name or a transposed digit is a far more likely explanation than fraud.

One caution worth stating plainly. A mismatch is not evidence about anyone's work authorization or immigration status, and treating it as if it were creates a discrimination problem on top of whatever you started with. Correct the record, ask the employee to check their own details, and keep the conversation about accuracy.

Still Using Spreadsheets for Onboarding?
Automate documents, training assignments, task management, and track onboarding progress in real time.
See How It Works

Identity Fraud at the Hiring Stage

Identity fraud at hire is the version most small employers have never considered: the person doing the job is not the person whose identity you verified. The paperwork passes because the identity itself is real, borrowed or bought from an actual person, and remote roles remove the one check that used to happen automatically, which was seeing the same face every morning.

This stopped being a theoretical risk. On June 30, 2025, the Department of Justice announced coordinated nationwide actions against schemes in which North Korean IT workers obtained remote jobs at US companies using stolen and fabricated identities, helped by facilitators inside the United States.

What the Case Files Actually Describe
Per the Justice Department announcement of June 30, 2025, the schemes reached more than 100 US companies, used the identities of more than 80 US persons, and generated more than $5 million in revenue. Victim companies incurred at least $3 million in legal fees, remediation costs and damages. The mechanics are the part worth reading twice: US-based facilitators created shell companies with matching websites, hosted company laptops at their own homes, and used remote access switches so the work appeared to come from a US address.

The uncomfortable detail is that none of the standard checks are designed to catch this. Each one answers a narrower question than employers assume it does.

CheckWhat it actually verifiesWhat it does not catch
Form I-9That documents from the acceptable lists were presented and appear genuine and related to the personA genuine document belonging to someone else, presented by a person who resembles the photo
E-VerifyThat the name, date of birth and number match government records and are authorized to workThat the applicant is the person those records describe
E-Verify photo matchingThat the photo on file matches the document shown, for four List A documentsAnything, when a different document is used or when nobody compares the faces carefully
Background checkHistory attached to the identity that was submittedWhether the identity belongs to the applicant at all
Reference checksThat named people confirm the work history describedReferences supplied and answered by the same fraud network
Video interviewThat a person appeared and answeredA proxy on camera, or a different person doing the job afterward

Photo matching is the strongest of these and it is narrow. It displays the government photo on file when the employee presents one of four List A documents: the US passport, the passport card, the Permanent Resident Card and the Employment Authorization Document. It also depends entirely on a human comparing the faces rather than clicking through.

What works better is watching for the operational signals that identity checks miss. A home address that does not match the bank account name. A request to ship equipment somewhere unconnected to the employee. Reluctance to appear on camera, or a camera that behaves oddly during the hiring process. A direct deposit change in the first two weeks. None of these proves anything alone, and together they are worth a phone call before the first payroll run.

One boundary matters here. If something looks wrong, you cannot demand extra or specific documents beyond what the Form I-9 process allows, because refusing valid documents or asking for particular ones is its own violation. Verify the person through the parts of the process you control, such as a live video conversation and the address and payment details, rather than by escalating document demands.

What worked for me
The change that made the most difference for us cost nothing: one live video conversation with camera on, scheduled before the offer rather than after, with the person asked to talk through a piece of work in their own words. Not a test, and not a trap. Two things came out of it. Almost every genuine candidate was more comfortable after it than before, because talking about real work is easier than answering interview questions. And the one time something felt wrong, the discomfort showed up in exactly this call, in the gap between the CV and the way the person described their own project. I do not think of it as a fraud control when I schedule it. It just happens to be one.

Your Liability When Employee Data Is Stolen From You

If employee data leaks from your systems, you own the consequences on two tracks at once: statutory notification, and a common law duty of care that courts have been willing to recognize. This is the direction where employee identity theft turns into your legal problem rather than someone else's misfortune.

Notification is the first track. Every state and the District of Columbia has a breach notification law, the duty normally falls on the business that owns the data rather than the vendor holding it, and the deadline follows the affected person's state of residence. The mechanics are covered in our guide to employee data privacy, and the short version is that a vendor incident usually becomes your letter with your name at the top.

The second track is negligence. In Dittman v. UPMC, decided by the Pennsylvania Supreme Court in 2018, employees whose records were stolen sued their employer after the data was used to file fraudulent tax returns. The court recognized a duty to exercise reasonable care to safeguard employee data stored on an internet-accessible computer system, reasoning that the employer had required that data as a condition of employment.

That holding binds Pennsylvania, not the country. Treat it as the direction of travel rather than a national rule, and note the logic, which travels well: you compelled people to hand over the data, so you carry an obligation to look after it.

FailureHow it usually happens at a small companyWhat it turns into
Bulk employee data emailed outA message that appears to come from an owner asks payroll for copies of every W-2Fraudulent tax returns filed in your employees’ names, and a notification obligation
Access never removedA departing employee keeps credentials to the HR or payroll system for weeksAn avoidable breach with a clear, documented failure behind it
Vendor incidentA payroll, benefits or screening provider is compromisedYour notification project, on your deadline, paid for by whoever your contract says
Documents kept foreverScanned IDs and old background reports stay in a shared folder indefinitelyA larger blast radius and a harder conversation about why you still held it
Insecure disposalPaper files or old drives discarded without shredding or wipingA disposal rule violation, and identity data recoverable by anyone who wants it

The last row has a specific rule behind it. Information derived from a background check run by a screening company must be disposed of under the FTC disposal rule (16 CFR 682.3), by shredding or wiping rather than recycling, so that it cannot practicably be read or reconstructed. The same standard is a sensible default for everything else in the personnel file.

The Controls That Prevent Most of It

Eight controls close nearly all of the realistic routes, and the two that matter most take an afternoon and cost nothing. This is the whole program for a business without a dedicated HR department.

1
Never move employee data because an email asked
Requests for W-2 copies, Social Security numbers or bank details get confirmed by voice on a number already on file. State the rule publicly so nobody feels awkward applying it to a message that appears to come from the owner.
2
Change bank details only through authenticated self-service
Either the employee changes them in a portal after logging in, or you call them back on the number in their record. Never on the strength of an email, however normal it looks.
3
Collect the sensitive fields once, in one place
Numbers and scanned IDs live in one system with a real permission model, not in email threads and a shared spreadsheet. Every extra copy is another place to lose it.
4
Restrict who can open what
Payroll sees bank details. Managers see contact details. Nobody browses the whole file because it is easier than asking. Review the list whenever somebody changes roles.
5
Kill access on the last day
Systems, email, and the HR platform, on the termination date rather than at the end of the month. A former employee with live credentials is the most preventable breach there is.
6
Verify the human at hire, not just the identity
One live video conversation, an address and payment check that agree with each other, and equipment shipped only to the employee. Do this without demanding extra documents.
7
Put a retention and disposal date on identity documents
Decide how long scanned IDs and background reports stay, then actually destroy them by shredding or wiping. Data you no longer hold cannot be stolen from you.
8
Ask vendors the uncomfortable questions before signing
Where the data sits, who can open it, how fast they tell you after an incident, and who pays for notification. Get the answers in writing and revisit them at renewal.

Two of those are worth singling out. The bulk-data rule and the bank-detail rule together close the routes behind most employer-side incidents, and neither requires software, budget or a policy document longer than a paragraph.

The rest is mostly a consequence of where the data lives. When employee records sit in one system with role-based permissions and an audit trail, most of this list is configuration rather than discipline, which is the argument for consolidating self-service and records instead of running five disconnected tools. FirstHR is an onboarding and HR platform, not a payroll provider, so the payroll-side rules above still need to be agreed with whoever runs your pay runs.

Companies Using FirstHR Onboard 3x Faster
Join hundreds of small businesses who transformed their new hire experience.
See It in Action

What to Do When an Employee Reports It

Do two things in parallel: check whether your systems are the source, and make the employee's recovery easy. Those are separate jobs, and confusing them is how a supportive conversation turns into an interrogation.

The internal check is a short list. Look at their record for unauthorized changes to address or bank details, review who has opened it and when, look for any bulk export or emailed request for payroll data in the period, and confirm that nobody who left still has access. If a vendor sent you an incident notice in the same window, that is a lead rather than a coincidence.

The employee-facing half is mostly logistics. Give them their own wage records for the periods in question, written confirmation of employment dates and location, and paid time to make the calls, because every one of these organizations answers the phone during business hours only.

The four routes worth handing an employee, in this order
Report it once, in the place that produces a plan
IdentityTheft.gov, run by the Federal Trade CommissionIt generates a personal recovery plan and the affidavit that banks and creditors ask for. Everything else is easier once this exists.
Protect the tax filing
The IRS: an Identity Protection PIN, plus Form 14039 if a fraudulent return was already filedA CP01E notice on its own means employment misuse with no known effect on the tax account, so an affidavit is not automatically needed.
Check the earnings record
The Social Security AdministrationWages the employee never earned can attach to their record and distort future benefits. Reviewing it early is far easier than correcting it at retirement.
Lock the number against future employment checks
Self Lock, inside a myE-Verify accountA locked number returns a mismatch when another employer runs an E-Verify case on it. The employee unlocks it themselves when they change jobs.
Give this as a list, not as advice about their particular situation. Your part is to make the first hour easy and to answer for the records you hold.

Self Lock deserves a note, because it is the one most people have never heard of. It sits inside a myE-Verify account, the worker-facing side of E-Verify, and places a lock on a Social Security number so that a case run by another employer returns a mismatch. The employee controls it and unlocks the number when they genuinely change jobs. The E-Verify Self Lock page explains the mechanics.

Three things not to do. Do not ask the employee to prove it with extra documents, because you are not the adjudicator here. Do not discuss it with anyone who does not need to know, since the information involved is exactly what was misused. And do not close the loop silently: tell them what you checked and what you found, even when the answer is that your systems look clean.

Write it down as it happens. The dates, the checks you ran and what you handed over are the parts you will be asked about later, and none of it is reconstructable from memory a year on.

Employee Identity Theft Report and Response Log
EMPLOYEE IDENTITY THEFT REPORT AND RESPONSE LOG

Open this the day an employee tells you their identity has been misused, or the
day you find a mismatch you cannot explain. Record facts and dates only. Keep it
with restricted access, because it will contain exactly the data that was
misused in the first place.
Business: [Company Name]
Opened by: Title:
Date opened:
Employee affected: Employee ID:
1. WHAT WAS REPORTED

How we learned about it: [ ] Employee told us [ ] IRS or SSA notice shown to us
[ ] Wage report mismatch [ ] Vendor notified us
[ ] Other:
Date the employee first noticed something:
Date they told us: Told to:
In their own words:
Documents they showed us (do not keep copies unless there is a reason):
2. IS THIS ABOUT EMPLOYMENT OR ABOUT OUR RECORDS

Someone else appears to be working under their number: [ ] Yes [ ] No [ ] Unknown
Wages reported that they did not earn: [ ] Yes [ ] No [ ] Unknown
Any sign the data came from us or from one of our vendors: [ ] Yes [ ] No [ ] Unknown
If yes, what points that way:
3. WHAT WE CHECKED IN OUR OWN SYSTEMS

Record each check, who ran it, and the date.
Their record for unauthorized changes (address, bank details, contact):
Payroll change log for the last 12 months:
Who has opened their record, and when:
Any bulk export of employee data in the period:
Any request for W-2 copies or payroll files by email:
Access still active for anyone who has left:
Vendor incident notices received in the period:
4. WHAT WE GAVE THE EMPLOYEE

[ ] Copies of their own wage records for the periods in question
[ ] Written confirmation of their employment dates and locations
[ ] The recovery route list (FTC, IRS, SSA, E-Verify Self Lock)
[ ] Paid time to make the calls
[ ] Identity protection service, if we offer one Enrolled on:
Nothing extra was demanded from them as proof: [ ] Confirmed
5. IF OUR SYSTEMS WERE THE SOURCE

Date we determined a breach occurred:
States the affected people live in:
Counsel contacted: Date:
Notification deadline that applies:
Regulator notice required: [ ] Yes [ ] No Sent:
Insurer notified: Date:
6. CLOSE-OUT

What we changed as a result:
Control added or tightened: Owner: Date:
Employee updated on the outcome: Date:
Record filed at: Access restricted to:
DISCLAIMER: This is a sample record for general information only and is not
legal advice. Notification duties, deadlines and the right response depend on
the facts and on the law of each affected person's state. Get advice on your own
situation before acting on anything recorded here.

Identity Theft Protection as an Employee Benefit

Identity theft protection is a cheap benefit that monitors credit files and identity records, alerts the employee to new activity, and provides restoration help when something goes wrong. The tax treatment is settled and favorable, which is the part most owners do not know.

IRS Announcement 2015-22 stated that the IRS will not assert that an employer providing identity protection services to employees whose information may have been compromised in a breach of the employer's recordkeeping system must include the value in employees' gross income and wages, or report it on an information return such as Form W-2. Announcement 2016-02 extended the same treatment to services provided before any breach occurs.

That second announcement is what makes this usable as an ordinary voluntary benefit rather than something you scramble to buy after an incident. Note the boundary the guidance draws: it does not cover cash paid in lieu of the services, or proceeds received under an identity theft insurance policy.

What these services doWhat they do not doWhy it matters to you
Monitor credit files and alert on new activityPrevent the theft from happeningDetection speed is the variable that decides how bad it gets
Provide restoration specialists who do the paperworkMake the decisions, which the employee still has to sign off onThe restoration hours are the real product, and they otherwise come out of work time
Often reimburse certain recovery expensesCover every loss automatically, since each policy sets its own limitsRead the schedule before quoting any figure to your team
Cover the employee, often with a family optionProtect your company recordsYour systems still need the controls above, whatever the benefit says

The honest read on adoption is that this is a low-cost, low-usage benefit. It is worth offering because the downside is small and the moment you need it, you need it immediately. If your systems were the source of a breach, offering it stops being optional in practice, whatever the law requires.

Where Employers Get This Wrong

Five patterns, and the first two account for most of the damage at companies without a dedicated HR person.

The Recurring Failures
Treating a request for bulk employee data as routine because it appears to come from someone senior. Leaving access live after somebody leaves, which is the most preventable breach there is. Assuming identity checks verify identity, when the I-9 and E-Verify confirm that a real, authorized identity exists rather than that the applicant owns it. Keeping scanned IDs forever, so a breach five years from now exposes people who left long ago. And treating an employee's report as their private problem, when the first question is always whether your own systems were the source.

The last one is the one I got wrong. My instinct with that IRS letter was sympathy, when the useful response was a two-hour check of our own records followed by sympathy. Both are needed, and only one of them tells you whether you have a problem of your own.

Key Takeaways
Employee identity theft covers three different problems: misuse of an employee’s number elsewhere, an applicant hired under a stolen identity, and staff records stolen from your systems.
Employment-related identity theft reaches employees through IRS notices such as the CP01E, and the useful thing you hold is proof of what they actually earned with you.
The Social Security Administration discontinued its no-match letters in April 2021, so a name and number mismatch now surfaces only when someone looks at a wage report.
Form I-9 and E-Verify confirm that an authorized identity exists, not that the applicant owns it, and photo matching applies to only four List A documents.
Breach notification duties normally fall on the business that owns the data, and a Pennsylvania decision recognized an employer duty of reasonable care over employee records.
Two free rules close most employer-side routes: no bulk employee data leaves on the strength of an email, and bank details change only through authenticated self-service or a callback.

Frequently Asked Questions

What is employee identity theft?

Employee identity theft is the misuse of a worker’s personal identifying information in a way that touches employment, and it arrives from three directions that share almost nothing except the name. In the first, a stranger works somewhere else under your employee’s Social Security number, which the IRS calls employment-related identity theft. In the second, an applicant is hired using an identity that belongs to someone else, so the documents check out and the person does not. In the third, staff data is stolen out of your own records, which is the only version that creates direct legal duties for the employer. Each one needs a different response, and treating them as a single problem is why most small companies have no plan for any of them.

What does it mean when the IRS tells an employee someone used their Social Security number for work?

It means the IRS has matched wages to that number that the employee did not earn, which it flags with a CP01E notice. The IRS states there is no known impact on the person’s tax account, places an identity theft indicator on it, and monitors for further activity, so this notice is informational rather than a bill. Employees may also see it as a CP2000 or CP2057 notice about unreported income, or as a Form W-2 arriving from a company they never worked for. Practical steps for the employee are to get an Identity Protection PIN, review the Social Security earnings record for wages they never earned, and consider locking the number against future employment checks. As the employer, the useful thing you hold is proof of what they actually earned with you.

Is an employer liable if employee data is stolen in a data breach?

Often yes, on two separate tracks. Every state plus the District of Columbia has a breach notification statute, and the duty to notify normally falls on the business that owns the data, which means a breach at your payroll or benefits vendor usually becomes your notification project on your deadline. Beyond notification, courts have recognized that collecting sensitive data as a condition of employment creates an obligation to protect it. In Dittman v. UPMC, the Pennsylvania Supreme Court held in 2018 that an employer has a duty to exercise reasonable care to safeguard employee data stored on an internet-accessible system, in a case where stolen records were used to file fraudulent tax returns. Read your vendor contracts for who pays notification costs before you need the answer.

Can E-Verify stop someone from being hired with a stolen identity?

No, not reliably, because E-Verify checks whether the identity is authorized to work rather than whether the applicant is that person. A real name, date of birth and Social Security number belonging to someone else will generally clear the system. Photo matching narrows the gap by displaying the government photo on file for four List A documents, the US passport, the passport card, the Permanent Resident Card and the Employment Authorization Document, so the reviewer can compare it to the document presented. That helps only when one of those four documents is used and only when a human actually compares the faces. The other half of the defense is procedural: verify the identity in a live video call, confirm the address and bank details match the person, and never let equipment ship somewhere unconnected to the employee.

What should we do if an employee tells us their identity was stolen?

Start by finding out whether your systems are implicated, then help rather than investigate. Check the employee’s record for unauthorized changes to address or bank details, review who has opened it, and look for any bulk export or emailed request for payroll data in the period. Give the employee copies of their own wage records, written confirmation of their employment dates, and paid time to make the calls, because the recovery work happens during business hours. Hand them the four routes: IdentityTheft.gov for the recovery plan, the IRS for an Identity Protection PIN, the Social Security Administration to review the earnings record, and E-Verify Self Lock to block future employment checks. Do not demand extra documents as proof, and do not discuss it with anyone who does not need to know.

Is employer-paid identity theft protection taxable to employees?

No, according to IRS guidance the value does not have to be included in employees’ gross income and wages. Announcement 2015-22 addressed identity protection services provided to employees whose information may have been compromised in a breach of the employer’s recordkeeping system, and stated that the IRS will not assert that the value belongs in gross income and wages or on an information return such as Form W-2. Announcement 2016-02 extended the same treatment to services provided before any breach happens, which is what makes this practical as an ordinary benefit rather than an apology gift. The guidance does not cover cash paid in lieu of the services or proceeds received under an identity theft insurance policy, so keep the benefit as a service.

How do we stop employee W-2 and payroll data from leaving the company?

Make bulk employee data something that never moves because an email asked for it. The recurring scam is a message that appears to come from an owner or executive asking payroll to send copies of every W-2, and it works because the request looks routine and slightly urgent. Write one rule and state it publicly so nobody feels awkward enforcing it: requests for employee tax forms, Social Security numbers or bank details are confirmed by voice on a number already on file before anything is sent, no exceptions for senior people. Pair it with the related control on the payment side, which is that direct deposit changes happen only through an authenticated self-service portal or a callback. Both cost nothing and close the two routes that account for most of this.

Ready to transform your onboarding?

7-day free trial No credit card required
Start Your Free Trial