Trinity Health, a multi-institutional Catholic health care system, disclosed a security incident involving its third-party vendor, Accellion. On January 29, 2021, Accellion notified Trinity Health of a flaw in its File Transfer Appliance. An unknown user exploited this vulnerability to download files containing protected health information (PHI), including patient names, addresses, dates of birth, medical record numbers, and financial data. Trinity Health took the appliance offline, launched an investigation, and offered one year of complimentary credit monitoring and identity theft restoration services to affected patients.