Hillsides, a California-based social services organization, disclosed that an employee sent internal spreadsheets containing PII (names, SSNs, addresses, phone numbers) and PHI (client names, birth dates, treatment data) to a personal email account between October 2014 and October 2015. The employee was terminated. Data was sent unencrypted. No evidence of further misuse was found, but notification was sent to affected staff and clients.