HackingCustomer Data InvolvedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNTMediumContained
American Renal Management
bd_35997c3cb5ad9235 · schema v1 · pii pii-v1
Full breach record for American Renal Management →American Renal Management LLC d/b/a Innovative Renal Care notified the Maryland AG of a data event where an unauthorized actor accessed systems between Feb 21 and Mar 1, 2024. Potentially affected data includes names, SSNs, medical info, and health insurance info. 464 Maryland residents were notified on Feb 14, 2025. The company engaged federal law enforcement and provided 12 months of credit monitoring.
Maryland clock✗ MD AG >90d50 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_018bb2bbc9352350Indiana State AGfiled 2025-02-14Verified
- bd_156b6fbcb36703c8California State AGfiled 2025-02-14Candidate
- bd_2d7a9d92dc429d4bMaine State AGfiled 2025-02-14Verified by operator
- bd_7217c4d2e2a0d45dVermont State AGfiled 2025-02-14Verified
Source provenance
- Source URL
- https://oag.maryland.gov/resources-info/SBN%20Documents/2025/ITU-376363.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2025
- Raw hash
- 03db2b2348a8c262adf6b57819166646caa2ae364a897f9012a1da41845c0af0
Reporting entity
- Name
- Mullen Coughlin LLCnorm: mullen coughlin
Victim entity
- Name
- American Renal Managementnorm: american renal management
Incident
- Discovered
- Feb 29, 2024
- Materiality determined
- —
- Notification sent
- Feb 14, 2025
- Affected individuals
- 464
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified federal law enforcement regarding the incidentProviding written notice of this incident to relevant state and federal regulators
Compliance
- Time to disclose
- 50 weeks(351 days from discovery to filing)
- Compliance flags
- MD AG >90d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.