Academic HealthPlans, Inc. notified California regulators of a phishing incident targeting employee email accounts between August 6, 2020, and October 2, 2020. The breach involved unauthorized access to Microsoft Office 365 accounts, potentially exposing customer PHI and basic identity information. No evidence of data exfiltration was found, but the company engaged Kroll to provide one year of complimentary identity monitoring to affected individuals.