Cyber Incident Victim: Anatomic and Clinical Laboratory Associates
Date:
Dec 2025
Location:
United States of America
Summary
Anatomic and Clinical Laboratory Associates notified nearly 170,000 patients after discovering unauthorized access to its network during a routine security review. The investigation confirmed that personal and protected health information, including names, dates of birth, Social Security numbers, taxpayer identification numbers, service dates, provider names, medical conditions, treatment details, diagnoses, medical history, account numbers and record numbers, had been exposed. Notification letters were sent to affected individuals and complimentary credit monitoring and identity theft protection were offered to those whose data included specific identifiers. The organization subsequently implemented additional security controls to reduce the risk of similar incidents.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On December 1, 2025, Anatomic and Clinical Laboratory Associates, a physician‑owned pathology group located in Nashville, Tennessee, detected anomalous activity within its computer network and promptly launched an investigation. The organization enlisted third‑party cybersecurity experts to assist with the investigation and to help secure its systems against further intrusion. During the investigation, analysts confirmed that an unauthorized party had gained access to the network, although the breach notice does not specify when the intrusion began or how long the network remained compromised. This initial detection marked the start of the formal response to the cybersecurity incident.

The review of the potentially exposed data was completed on April 27, 2026, at which point the investigators confirmed that personal and protected health information had been exposed. The exposed data included the names of affected individuals combined with one or more of the following elements: date of birth, Social Security number, taxpayer identification number, date(s) of service, medical provider name(s), mental or physical condition, medical treatment or procedure information, diagnosis or clinical information, medical history, patient account number, and/or medical record number. According to the breach notice, a total of 169,626 current and former patients had their information compromised in the incident. This number represents nearly 170,000 individuals whose protected health information was potentially accessed by an unauthorized party.
Notification letters were mailed to the affected individuals on June 23, 2026, informing them of the breach and the specific data elements that may have been exposed. As part of the response, Anatomic and Clinical Laboratory Associates offered complimentary credit monitoring and identity theft protection services to certain individuals, with the eligibility for these services determined by the types of information involved in each case. Following the notification, the organization stated that it had implemented additional security measures to prevent similar incidents from occurring in the future. The breach notice did not provide further details about the attacker’s identity, the specific vulnerability exploited, or any observed misuse of the exposed information.
