Skip to content

Clinical Pathology Laboratories

Disclosed Jul 15, 20197 years ago1,733,836 affectedConfirmed

Official notice

Clinical Pathology Laboratories, Inc., the covered entity (CE), reported that its business associate (BA), Retrieval-Masters Creditors Bureau, Inc., doing business as American Medical Collection Agency, was the victim of a cyber-attack that affected the electronic protected health information (ePHI) of 34,424 individuals. The ePHI involved included names, addresses, phone numbers, birthdates, treatment information, and financial data. The CE notified HHS, affected individuals, the media, and provided complimentary credit monitoring and identity theft mitigation services. The CE ended its business relationship with the BA.

What is known

People affected1,733,836 (as reported to HHS)
DisclosedJul 15, 2019
DiscoveredMay 15, 2019
HappenedAug 1, 2018
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
California AGresidents of CAJul 15, 2019
Washington AGresidents of WAJul 15, 20191,155
HHS archivetotalJul 15, 20191,733,836
Oregon DOJresidents of ORJul 16, 2019
History of this record
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: empty to hhs · backfill source
  • 2026-09-25 · records: empty to 1733836 · backfill source
  • 2026-09-25 · summary: empty to Clinical Pathology Laboratories, Inc., the covered entity (CE), reported that its business associate (BA), Retrieval-Masters Creditors Bureau, Inc., doing business as American Medical Collection Agency, was the victim of a cyber-attack that · backfill source
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · discovered: empty to 2019-05-15 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Clinical Pathology Laboratories

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.