Molina Healthcare of California, Inc. reported a breach involving Protected Health Information (PHI) and member identifiers. A former CVS employee, acting as a vendor, exfiltrated data from CVS computers on or about March 26, 2015, to fraudulently obtain OTC products. The breach exposed names, CVS IDs, and Rx plan numbers. Molina notified affected members on September 17, 2015, offering identity theft protection and card replacements.