Prentke Romich Company
bd_848e7cd93d7ca5ec · schema v1 · pii pii-v1
Full breach record for Prentke Romich Company →Prentke Romich Company dba PRC-Saltillo notified California residents of a data breach where an unauthorized actor copied files from its network between August 14 and August 21, 2024. The company became aware of suspicious activity on August 21, 2024. Affected data may include names, addresses, phone numbers, dates of birth, treatment cost information, referring/treating physician, health insurance policy numbers, Medicare/Medicaid plan names, and medical device purchases. Social Security numbers and financial account information were not impacted. The company secured systems, investigated the incident, and offered credit monitoring.
Linked disclosures
Why this link?Ransomware claims (1)
- bd_96781319d3fe8f86Leak Sitefogfiled 2024-09-18(6d gap)Verified
Regulatory filings (6) · sorted by filing gap
- bd_3534a44b64948843HHS OCRfiled 2024-09-25Verified
- bd_89db2b0c000a38ceWashington State AGfiled 2024-09-25Verified
- bd_05a162b64afeee2cIndiana State AGfiled 2024-09-12(13d gap)Verified
- bd_09af3448d15112fbMontana State AGfiled 2024-09-12(13d gap)Verified by operator
Show 2 more filings ↓Show fewer ↑up to 13d gap
- bd_347c6a13e03a974dNew Hampshire State AGfiled 2024-09-12(13d gap)Verified
- bd_6b1745cca9569fa6Vermont State AGfiled 2024-09-12(13d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-592423
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 25, 2024
- Raw hash
- f5cf6fc356acba2f00915cd6ec5251b2e53a5a342d1c569b594f0ef5f8819880
Reporting entity
- Name
- Prentke Romich Companynorm: prentke romich
- Domain
- prentrom.com
Victim entity
- Name
- Prentke Romich Companynorm: prentke romich
- Domain
- prentrom.com
Incident
- Discovered
- Aug 21, 2024
- Materiality determined
- —
- Notification sent
- Sep 12, 2024
- Affected individuals
- Not disclosed
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 5 weeks(35 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 22d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Aug 21, 2024→ Notified: Sep 12, 202422d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.