DisclosureLens
PhysicalHealthcareProfessional ServicesHealthcareTheftCustomer Data InvolvedEmployee Data InvolvedIdentity (basic)Government IDFinancial accountHealth (basic)PHIMediumContained

Renew Wellness Center, PLLC

bd_68327f406c319e39 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Jan 23, 2020

Filed

Mar 23, 2020

To disclose

9 weeks

Affected

726state residents only

Linked

2 filings

Confidence

66%
Full breach record for Renew Wellness Center, PLLC

Renew Wellness, LLC reported the theft of two unsecured counselor cell phones from its office on January 23, 2020. The phones provided access to a Gmail account containing client PII (names, addresses, SSNs) and PHI (medical diagnoses). Carriers blocked access shortly after theft. No evidence of actual unauthorized access was found, but notifications were sent out of caution. Kroll identity monitoring was offered.

Incident timeline

discovery → filing · 9 weeks / 60 days

Jan 23, 2020

Begins

Jan 23, 2020

Discovered

Mar 23, 2020

Filed

vs. sector median

2 wks faster

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (1) · sorted by filing gap

Filing propagation · 2 filings

View merged incident ↗
HHS OCRMar 23 · first
Montana State AGMar 23 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.