Valley Mountain Regional Center detected a malicious phishing email on September 15, 2021, which compromised 14 email accounts. The incident potentially exposed protected health information (PHI) including names, addresses, dates of birth, UCI numbers, and medical diagnoses for clients served by the regional center. The organization removed the phishing email, investigated the compromised accounts, and notified affected individuals.