MisusePrivilege AbuseEmployee Data InvolvedCustomer Data InvolvedIDENTITY_BASICPHIHEALTH_BASICLowActive
Mellow
bd_714778106e4fb93b · schema v1 · pii pii-v1
Full breach record for Mellow →Mellow Massage Hollywood disclosed an insider breach involving a former employee who unauthorizedly accessed and texted patient contact information (name, email, phone) from his new practice. The incident was discovered on January 3, 2024, when patients reported receiving texts from the former provider. The organization confirmed that payment information was not accessed, but potential exposure of personal medical files is under investigation. Law enforcement has been notified.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-578784
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 3, 2024
- Raw hash
- f33c68d5137aefbe4883d7539d3935b2ede4c5a0525aa054ae3d083bdb033128
Reporting entity
- Name
- Mellownorm: mellow
- Domain
- mellow-massage.com
Victim entity
- Name
- Mellownorm: mellow
- Domain
- mellow-massage.com
Incident
- Discovered
- Jan 3, 2024
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICPHIHEALTH_BASIC
- Attack vector
- Insider
- Threat actor
- Internal
- Regulator citations
- Contacting state and federal authorities
- Initial access
- insider_action
Compliance
- Time to disclose
- ≤1 day(0 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.