Skip to content

Quest Diagnostics

Disclosed Oct 25, 20241 year ago1,062 affectedConfirmed

Official notice

The covered entity (CE), Quest Diagnostics, reported that an employee misconfigured a website that allowed the protected health information (PHI) of 1,062 individuals to become viewable by others. The PHI involved included names, addresses, health insurance information, and treatment information. The CE notified HHS and the affected individuals. In response to the breach, the CE implemented additional administrative, technical, and security safeguards. Staff were also provided additional cybersecurity training.

What is known

People affected1,062 (as reported by the organization)
DisclosedOct 25, 2024
HappenedAug 8, 2024
AttackInsider
Data exposedNames, Health
SectorHealthcare · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
Indiana AGresidents of INOct 25, 202412
HHS archivetotalOct 25, 20241,062

Other breaches at Quest Diagnostics

BreachAffected
Disclosed Nov 16, 2021Nov 16, 20214 years ago5,325
Billing vendor AMCA breach exposes data of 11.9 million Quest patientsJun 3, 20197 years agoVendor breach12M
Disclosed Dec 12, 2016Dec 12, 20169 years agoHacking34K
Disclosed Dec 19, 2014Dec 19, 201411 years agoUnknown
History of this record
  • 2026-09-25 · attack: unknown to insider · backfill source
  • 2026-09-25 · data_types: [] to ["names","health"] · backfill source
  • 2026-09-25 · summary: empty to The covered entity (CE), Quest Diagnostics, reported that an employee misconfigured a website that allowed the protected health information (PHI) of 1,062 individuals to become viewable by others. The PHI involved included names, addresses, · backfill source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (Indiana AG), confirmed by Indiana AG. Record counts are as reported. Not legal advice.

Everything about Quest Diagnostics

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.