Hospice by the Bay notified the California Attorney General of a data breach occurring on March 10, 2020. An unauthorized individual sent a phishing email impersonating an employee to obtain an electronic report containing personal health information, including names, medical record numbers, insurer names, and service charges. Social Security numbers were not impacted. The organization strengthened employee training and internal policies in response.