Skip to content

Quest Diagnostics

Disclosed Dec 12, 20169 years ago34,055 affectedConfirmed

Official notice

The covered entity (CE), Quest Diagnostics, reported that it was the victim of a cyber-attack that affected the electronic protected health information (ePHI) of 34,055 individuals. The ePHI involved included names, dates of birth, telephone numbers, and lab results. The CE notified HHS, affected individuals, and the media. In response to the breach, the CE implemented additional administrative and technical safeguards to better protect its ePHI. OCR obtained assurances that the CE implemented the corrective actions noted.

What is known

People affected34,055 (as reported to HHS)
DisclosedDec 12, 2016
DiscoveredNov 28, 2016
HappenedNov 26, 2016
AttackHacking
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Source
California Attorney General breach notice: Quest Diagnosticsoag.ca.gov · Official notice
Oregon DOJ breach notice: Quest Diagnosticsjustice.oregon.gov · Official notice
Indiana Attorney General 2017 data breach report: Quest Diagnosticsin.gov · Official notice
HHS OCR breach report (archive, resolved): Quest Diagnostics (Healthcare Provider, NJ)ocrportal.hhs.gov · Official notice

Notices filed

WhereFiledPeople
California AGresidents of CADec 12, 2016
Oregon DOJresidents of ORDec 12, 201634,055
HHS archivetotalDec 12, 201634,055
Indiana AGresidents of INMar 27, 20171

Other breaches at Quest Diagnostics

BreachAffected
Disclosed Oct 25, 2024Oct 25, 20241 year agoInsider1,062
Disclosed Nov 16, 2021Nov 16, 20214 years ago5,325
Billing vendor AMCA breach exposes data of 11.9 million Quest patientsJun 3, 20197 years agoVendor breach12M
Disclosed Dec 19, 2014Dec 19, 201411 years agoUnknown
History of this record
  • 2026-09-25 · attack: unknown to hacking · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · records_basis: organization to hhs · backfill source
  • 2026-09-25 · records: 1 to 34055 · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Quest Diagnostics, reported that it was the victim of a cyber-attack that affected the electronic protected health information (ePHI) of 34,055 individuals. The ePHI involved included names, dates of birth, telephon · backfill source
  • 2026-09-25 · records_basis: empty to organization · backfill source
  • 2026-09-25 · records: empty to 1 · backfill source
  • 2026-09-25 · discovered: empty to 2016-11-28 · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Quest Diagnostics

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.