Skip to content

A2Z Diagnostics

Disclosed Jul 28, 20215 years ago35,587 affectedConfirmed

Official notice

The covered entity (CE), A2Z Diagnostics, reported that several employees were the victims of an email phishing scheme that compromised the protected health information (PHI) of 35,587 individuals. The PHI involved included names, addresses, dates of birth, drivers’ license and Social Security numbers, financial information, and diagnoses. The CE notified HHS, affected individuals, the media, and provided substitute notice. In its mitigation efforts, the CE provided complimentary credit monitoring services and implemented additional administrative and technical safeguards to better protect its PHI.

What is known

People affected35,587 (as reported to HHS)
DisclosedJul 28, 2021
HappenedFeb 2, 2021
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: A2Z Diagnosticsoag.ca.gov · Official notice
HHS OCR breach report (archive, resolved): A2Z Diagnostics (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CAJul 28, 2021
HHS archivetotalJul 28, 202135,587
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 35587 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), A2Z Diagnostics, reported that several employees were the victims of an email phishing scheme that compromised the protected health information (PHI) of 35,587 individuals. The PHI involved included names, addresses · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about A2Z Diagnostics

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.