AccidentalMisconfigurationCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
QUEST DIAGNOSTICS INCORPORATED
bd_314d12f96588f04e · schema v1 · pii pii-v1
Full breach record for QUEST DIAGNOSTICS INCORPORATED →Quest Diagnostics notified New Hampshire residents of a data incident involving an unintentional exposure of confidential data due to a coding configuration issue. The company implemented additional security controls, engaged an external cybersecurity consultant to validate fixes, and established a call center. Impacted patients were offered free identity monitoring services through Kroll, including credit monitoring and fraud restoration. No evidence of misuse was found.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6ba9e5f3e634abe2Indiana State AGfiled 2024-10-25Verified
- bd_a86690d20ebdc4fbMaine State AGfiled 2024-10-25Candidate
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/quest-diagnostics-20241025.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Oct 25, 2024
- Raw hash
- 39cb7b03c28890115528326340cd4e3b7419f9838bbc992b163763ed1b113433
Reporting entity
- Name
- QUEST DIAGNOSTICS INCORPORATEDnorm: quest diagnostics
Victim entity
- Name
- QUEST DIAGNOSTICS INCORPORATEDnorm: quest diagnostics
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- Oct 25, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Regulator citations
- Provided written notice of this incident to relevant state regulators
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.