Kaiser Permanente discovered on September 3, 2024, that an unauthorized party accessed the email accounts of two workforce members. The incident occurred between August and September 2024. Affected data included protected health information (PHI) such as names, dates of birth, medical record numbers, and medical information. Social Security numbers and credit card numbers were not involved. Kaiser terminated access and reset passwords.