California Massage Therapy Council (CAMTC) notified individuals of a potential data security incident involving its online payment page. CAMTC learned of the incident on February 22, 2021. The incident potentially exposed names, addresses, payment card numbers, expiration dates, and card security codes. CAMTC took its payment page offline, engaged a forensic firm, and migrated to a new payment platform. The occurrence date reported was November 4, 2020.