Bay Area Children's Association notified California AG of a breach involving its electronic medical record provider. Cyber intruders installed malware in January 2015 and used credential theft to access systems. Patient records potentially exposed include names, SSNs, DOBs, and health info. FBI and Secret Service are investigating. The organization provided 12 months of free credit monitoring and identity protection.