Hmm, another user recently reported an apparent failure of certbot renew
to update the symbolic links pointing to a recently renewed certificate. I wonder if you've got a certificate somewhere in /etc/letsencrypt/archive/
that covers all four subdomains, and the links just haven't been updated?
That's perfectly fine, as long as you don't have one domain with a large number of unrelated subdomains. If you do, you risk running into the rate limits, and while that won't hamper renewals, it might complicate obtaining certificates for any new subdomains.