Stanford University notified California AG that incorrect file permissions on a Graduate School of Business shared server exposed employee PII (SSN, DOB, salary) from Sept 2016 to March 2017. The breach was discovered by IT on Feb 23, 2017, but notification was delayed. Stanford secured the folders, engaged forensic investigators, and offered credit monitoring services to affected employees.