QUEST DIAGNOSTICS INCORPORATED
ent_019e20a59dfa5f55846c4084ee738e25
Disclosures
13
State AG · HHS OCR · 8 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
34,055
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- QUEST DIAGNOSTICS INCORPORATED
- Normalized
- quest diagnostics— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 8MCWUBXQ0WE04KMXBX50
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (13)newest first
- 🏛️Massachusetts State AGas victim2026-07-01
ExamOne, a Quest Diagnostics Company, notified Massachusetts residents of a breach involving specimens and paperwork for life insurance applications. Specimens and paperwork containing personal information (name, address, DOB, SSN last 4, driver's license, phone, physical measurements, medical history, medications, physician info) were not received by the testing laboratory as expected. No indication of theft or misuse, but risk exists. Credit monitoring and identity protection services offered for two years.
- 🏛️Massachusetts State AGas victim2026-05-01
ExamOne, a Quest Diagnostics company, notified Massachusetts residents via letter dated May 5, 2026, regarding a misdelivery of life insurance application paperwork. Specimens and paperwork containing personal information (name, address, DOB, last 4 digits of SSN, driver's license, phone, policy number, physical measurements, medications) were not received by the testing laboratory as expected. ExamOne stated there is no reason to believe information was stolen or misused, but offered 2 years of free Equifax credit monitoring. No specific count of affected individuals was disclosed in this notice.
- ⛰️New Hampshire State AGas victim2024-10-25
Quest Diagnostics notified New Hampshire residents of a data incident involving an unintentional exposure of confidential data due to a coding configuration issue. The company implemented additional security controls, engaged an external cybersecurity consultant to validate fixes, and established a call center. Impacted patients were offered free identity monitoring services through Kroll, including credit monitoring and fraud restoration. No evidence of misuse was found.
- 🏎️Indiana State AGas victim2024-10-25
Quest Diagnostics Incorporated reported a data breach to the Indiana Attorney General. The breach occurred on 2024-08-08 and was reported on 2024-10-25. 12 Indiana residents were affected. 1,062 individuals affected in total.
- 🦞Maine State AGas victim2024-10-25
Quest Diagnostics, Incorporated reported an inadvertent disclosure affecting 4 Maine residents. The breach occurred on August 8, 2024, and was discovered on August 27, 2024. The compromised information may include names, addresses, health data, health insurance information, and billing data. The company offered twelve months of identity monitoring services to those affected.
- 🦬Montana State AGas victim2021-11-16
Quest Diagnostics reported a data breach to the Montana Attorney General. The breach was reported on 2021-11-16. The breach occurred on 10/29/2021. 6 Montana residents were affected.
- 🐻California State AGas victim2021-11-16
On October 29, 2021, Quest Diagnostics experienced an inadvertent email misdelivery where an employee sent a spreadsheet containing personal information of current and former employees to internal distribution lists. The data included names, Social Security Numbers, employee ID numbers, and for some, personal email addresses. The company recalled the email, removed it from systems, and offered 12 months of identity monitoring.
- 🦞Maine State AGas victim2021-11-16
Quest Diagnostics reported an inadvertent disclosure of patient information on October 29, 2021, affecting 5,325 individuals, including 6 Maine residents. The breach involved names and Social Security Numbers. Quest Diagnostics notified affected individuals on November 16, 2021, and offered 12 months of credit monitoring through Experian.
- 🦬Montana State AGas victim2019-07-13
Quest Diagnostics, Inc. reported a data breach to the Montana Attorney General. The breach was reported on 2019-07-13. The breach occurred from 8/1/2018 to 3/30/2019. 7,488 Montana residents were affected.
- 🐻California State AGas victim2016-12-12
Quest Diagnostics notified patients of a breach affecting approximately 34,000 individuals. On November 26, 2016, an unauthorized third party accessed the MyQuest by Care360 internet application, obtaining PHI including names, dates of birth, lab results, and telephone numbers. The incident was discovered on November 28, 2016. No SSNs or financial data were compromised. Quest Diagnostics engaged a cybersecurity firm and reported the incident to federal law enforcement.
- 🦫Oregon State AGas victim2016-12-12
Quest Diagnostics reported a data breach to the Oregon Attorney General. The breach was reported on 2016-12-12. The breach occurred during 11/26/2016. The breach was discovered on 11/28/2016. 34,055 individuals were affected. Notice was sent on 12/12/2016.
- NJHHS OCRas victim2016-12-12
Quest Diagnostics (NJ healthcare provider) reported a hacking/IT incident affecting a network server that exposed the ePHI of 34,055 individuals. Data elements involved: names, dates of birth, telephone numbers, and lab results. The CE notified HHS, affected individuals, and the media, and implemented additional administrative and technical safeguards. OCR obtained assurances that corrective actions were implemented. No business associate involvement reported.
- 🐻California State AGas victim2014-12-19
Quest Diagnostics filed a data breach notification with the California Attorney General. The breach occurred on November 17, 2014. The provided source document contains only the filing metadata and an empty attachment placeholder; no narrative details regarding the nature of the breach, data types affected, or number of individuals impacted are available in the text.