GMGS Risk Management & Insurance Services discovered on December 21, 2020, that an employee's email account was accessed by an unknown individual. The incident potentially exposed PII (name, SSN, driver's license, DOB) and PHI (medical/health insurance info). Forensic investigation completed in Feb 2021; data review confirmed exposure in June 2021. GMGS implemented MFA and offered credit monitoring.