University of Minnesota Physicians reported a data security event where cyber attackers used phishing emails to fraudulently access two employee email accounts between January 30 and February 4, 2020. The incident potentially exposed patient and employee data including names, addresses, SSNs, medical records, and payment card numbers. UMPhysicians secured the accounts, engaged forensic investigators, and offered 12 months of identity monitoring.