DNA Diagnostics Center, Inc.
ent_f3371f8d5af36f0b85bfee2c
Disclosures
9
State AG · 9 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
2,102,436
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- DNA Diagnostics Center, Inc.
- Normalized
- dna diagnostics center— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- dnacenter.com
Disclosure history (9)newest first
- South Carolina State AGas victim2021-12-15
DNA Diagnostics Center, Inc. reported unauthorized access to an archived genetic testing database acquired in 2012. Access occurred between May 24 and July 28, 2021. The breach exposed SSNs and payment information for individuals who underwent testing between 2004-2012. DDC detected the incident on August 6, 2021, engaged forensic investigators, notified law enforcement, and began notifying affected individuals on October 29, 2021, offering credit monitoring.
- Oregon State AGas victim2021-12-09
DNA Diagnostics Center (DDC) reported a data breach to the Oregon Attorney General. The breach was reported on 2021-12-09. The breach occurred during 5/24/2021 - 7/28/2021. The breach was discovered on 10/29/2021. Notice was sent on 11/29/2021.
- New Hampshire State AGas victim2021-12-06
DNA Diagnostics Center, Inc. notified the NH AG of unauthorized access to an archived genetic testing database (inactive since 2012). Access occurred May-July 2021; detected Aug 6, 2021. ~176 NH residents affected (names, SSNs, some payment info). Notification sent Nov 29, 2021. Credit monitoring offered.
- Massachusetts State AGas victim2021-11-29
DNA Diagnostics Center, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2021-11-29. 1,048 Massachusetts residents were affected. The report records the breach type as electronic.
- Indiana State AGas victim2021-11-29
DNA Diagnostics Center, Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2021-05-24 and was reported on 2021-11-29. 4,871 Indiana residents were affected. 2,102,436 individuals affected in total.
- Maine State AGas victim2021-11-29
DNA Diagnostics Center, Inc. reported an external system breach (hacking) occurring between May 24, 2021, and July 28, 2021, discovered on October 29, 2021. The incident affected 2,102,436 individuals, including 225 Maine residents. Acquired data included names combined with financial account or credit/debit card numbers (with security codes/PINs). The company provided 12 months of identity theft protection services through Experian via substitute notice.
- Washington State AGas victim2021-11-29
DNA Diagnostics Center, Inc. (DDC) notified the Washington Attorney General of unauthorized access to an archived genetic testing database. The breach affected approximately 4,278 Washington residents, exposing names, Social Security numbers, and some credit/debit card information. Access occurred between May 24, 2021, and July 28, 2021, but was detected on August 6, 2021. DDC offered complimentary credit monitoring via Experian and advised individuals to place fraud alerts or security freezes.
- California State AGas victim2021-11-29
DNA Diagnostics Center, Inc. detected unauthorized access to an archived database on August 6, 2021. The investigation determined that an unauthorized individual accessed and potentially removed files containing personal information (including SSNs and payment info) collected between 2004 and 2012 from a previously acquired genetic testing organization. The access occurred between May 24, 2021, and July 28, 2021. The company contained the threat, engaged third-party cybersecurity experts, and coordinated with law enforcement. Affected individuals are being offered complimentary credit monitoring.
- Illinois State AGas victim2021-01-01
DNA DIAGNOSTICS CENTER, INC filed a data-breach notice with the Illinois Attorney General during 2021 (case 21-481). The register records the breach as discovered on May 24, 2021. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.