The threat actor used compromised credentials to download copies of personal data, though no clinical or patient medical data ...