Kaiser Permanente Northern CA Department of Research notified California regulators of a cybersecurity incident involving a research server infected with malicious software between October 2011 and February 2014. The breach potentially exposed patient research data including names, dates of birth, and medical record numbers, though SSNs were excluded. No unauthorized access was confirmed, but the server was removed and authorities alerted.