HackingCustomer Data InvolvedPHIHEALTH_BASICIDENTITY_BASICMediumContained
QUEST DIAGNOSTICS INCORPORATED
bd_574b0af29c73165e · schema v1 · pii pii-v1
Full breach record for QUEST DIAGNOSTICS INCORPORATED →Quest Diagnostics notified patients of a breach affecting approximately 34,000 individuals. On November 26, 2016, an unauthorized third party accessed the MyQuest by Care360 internet application, obtaining PHI including names, dates of birth, lab results, and telephone numbers. The incident was discovered on November 28, 2016. No SSNs or financial data were compromised. Quest Diagnostics engaged a cybersecurity firm and reported the incident to federal law enforcement.
California clockDiscovered Nov 28, 2016 → Notified Dec 12, 201614d ✓ CA 60-day OK14 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_6e2d72959974be37Oregon State AGfiled 2016-12-12Candidate
- bd_c638edd5d74b1ca8HHS OCRfiled 2016-12-12Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-65390
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2016
- Raw hash
- 336d62127eb594deb9b7cf0e230cfbc3575934aa04b24509b3761859f3f27e2a
Reporting entity
- Name
- QUEST DIAGNOSTICS INCORPORATEDnorm: quest diagnostics
- Domain
- questdiagnostics.com
Victim entity
- Name
- QUEST DIAGNOSTICS INCORPORATEDnorm: quest diagnostics
- Domain
- questdiagnostics.com
Incident
- Discovered
- Nov 28, 2016
- Materiality determined
- —
- Notification sent
- Dec 12, 2016
- Affected individuals
- 34,000
- Data types
- PHIHEALTH_BASICIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Reported the incident to federal law enforcement authorities
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 14 days(14 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 14d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Nov 28, 2016→ Notified: Dec 12, 201614d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.