Northern California Medical Associates, Inc. (NCMA) reported a cybersecurity incident involving unauthorized access to its network beginning February 19, 2021, and culminating in the encryption of servers and workstations on March 3, 2021. The incident involved ransomware deployment and subsequent data exfiltration. Potentially affected data included patient names, contact information, Social Security numbers, driver's license numbers, financial account information, and medical/health insurance records. NCMA shut down network portions, reset passwords, engaged forensic specialists, restored data, and notified law enforcement.