Anatomic and Clinical Laboratory Associates
Incident posture
Linked entities
- Victim
- Anatomic and Clinical Laboratory Associates
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Anatomic and Clinical Laboratory Associates disclosed a breach affecting approximately 170,000 current and former patients after detecting anomalous network activity and confirming unauthorized access. The subsequent review revealed that exposed information included names combined with dates of birth, Social Security numbers, taxpayer identification numbers, service dates, provider names, mental or physical health details, treatment and procedure data, diagnoses, medical history, patient account numbers and medical record numbers. Notification letters were sent to those impacted, and complimentary credit monitoring and identity theft protection were offered based on the data involved. The organization has since implemented additional security measures to reduce the risk of similar incidents.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On December 1, 2025, Anatomic and Clinical Laboratory Associates identified anomalous activity within its computer network and launched an investigation. The organization engaged third‑party cybersecurity experts to assist with the investigation and to help secure its systems. During the course of the investigation, unauthorized network access was confirmed, although the breach notice did not specify when the access began or how long the network remained compromised. The review of the potentially exposed data was completed on April 27, 2026, at which point it was determined that personal and protected health information had been exposed.
The breach affected 169,626 current and former patients of the Nashville, Tennessee‑based pathology group. Exposed information included patients’ names combined with one or more of the following data elements: date of birth, Social Security number, taxpayer identification number, date(s) of service, medical provider name(s), mental or physical condition, medical treatment or procedure information, diagnosis or clinical information, medical history, patient account number, or medical record number. No further details about the specific combination of data elements per individual were provided in the breach notice. The incident was described as involving protected health information, triggering notification under applicable health privacy regulations.
Notification letters were mailed to the affected individuals on June 23, 2026. As part of the response, the organization offered complimentary credit monitoring and identity theft protection services to certain individuals, based on the types of information involved in their exposure. After completing the review, Anatomic and Clinical Laboratory Associates stated that it had implemented additional security measures to prevent similar incidents in the future. The breach notice did not report any known misuse of the exposed data at the time of notification.
Sources
Sources available to members: 1 source.