Northern Trust inadvertently transmitted an encrypted file containing employee benefits plan participant information (name, address, SSN, account numbers, bank routing/account numbers) to a record-keeping company not responsible for that specific plan. The incident occurred on May 17, 2014. The recipient company's employee viewed the data, notified Northern Trust, and permanently deleted the file. No further dissemination occurred. Northern Trust offered one year of credit monitoring.