CSIDB logo
Incident

Anatomic and Clinical Laboratory Associates

Incident posture

Attack window
Dec 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-25 01:05

Linked entities

Victim
Anatomic and Clinical Laboratory Associates
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Dec 2025
Disclosed
Jun 2026
Resolved
Pending

Summary

Anatomic and Clinical Laboratory Associates disclosed a breach affecting approximately 170,000 current and former patients after detecting anomalous network activity and confirming unauthorized access. The subsequent review revealed that exposed information included names combined with dates of birth, Social Security numbers, taxpayer identification numbers, service dates, provider names, mental or physical health details, treatment and procedure data, diagnoses, medical history, patient account numbers and medical record numbers. Notification letters were sent to those impacted, and complimentary credit monitoring and identity theft protection were offered based on the data involved. The organization has since implemented additional security measures to reduce the risk of similar incidents.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On December 1, 2025, Anatomic and Clinical Laboratory Associates identified anomalous activity within its computer network and launched an investigation. The organization engaged third‑party cybersecurity experts to assist with the investigation and to help secure its systems. During the course of the investigation, unauthorized network access was confirmed, although the breach notice did not specify when the access began or how long the network remained compromised. The review of the potentially exposed data was completed on April 27, 2026, at which point it was determined that personal and protected health information had been exposed.

The breach affected 169,626 current and former patients of the Nashville, Tennessee‑based pathology group. Exposed information included patients’ names combined with one or more of the following data elements: date of birth, Social Security number, taxpayer identification number, date(s) of service, medical provider name(s), mental or physical condition, medical treatment or procedure information, diagnosis or clinical information, medical history, patient account number, or medical record number. No further details about the specific combination of data elements per individual were provided in the breach notice. The incident was described as involving protected health information, triggering notification under applicable health privacy regulations.

Notification letters were mailed to the affected individuals on June 23, 2026. As part of the response, the organization offered complimentary credit monitoring and identity theft protection services to certain individuals, based on the types of information involved in their exposure. After completing the review, Anatomic and Clinical Laboratory Associates stated that it had implemented additional security measures to prevent similar incidents in the future. The breach notice did not report any known misuse of the exposed data at the time of notification.

Sources

Sources available to members: 1 source.

CSIDB