On November 28, 2018, Verity Medical Foundation reported that a third party compromised an employee's Microsoft 365 email account for approximately 1.5 hours. The attacker sent emails with malicious Docusign links to obtain credentials. The intruder had access to the employee's email folders, which contained personal information including names, dates of birth, social security numbers, phone numbers, and addresses. The Foundation terminated access, disabled the account, and offered one year of credit monitoring.