Menu
Browse

Cyber Incident Victim: Nationwide Laboratory Services

Date:

May 2021

Location:

United States of America

Summary

A ransomware attack encrypted files at Nationwide Laboratory Services, prompting immediate containment measures and a third-party investigation. The breach exposed protected health information, including names, dates of birth, lab results, medical and Medicare numbers, and insurance details, with Social Security numbers compromised for some individuals among the 33,437 affected. While potential data exfiltration occurred, no evidence of misuse was found, leading the organization to offer credit monitoring to those with exposed SSNs. The incident aligns with FBI warnings about ransomware groups targeting companies during significant financial events like mergers and acquisitions.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On May 19, 2021, Nationwide Laboratory Services, a Boca Raton-based clinical laboratory later acquired by Quest Diagnostics, detected a ransomware attack that encrypted files across its network, blocking access to critical systems. The organization immediately implemented containment measures and engaged a third-party cybersecurity firm to investigate the breach and assist with remediation. Forensic analysis confirmed by August 31, 2021, that attackers had infiltrated network segments containing protected health information, potentially compromising data including patient names, dates of birth, lab test results, medical record numbers, Medicare identifiers, and health insurance details. A subset of affected individuals had their Social Security numbers exposed, with the specific data types varying per patient. The breach report filed with the Department of Health and Human Services’ Office for Civil Rights indicated 33,437 individuals were potentially impacted.

Cyber Incident Image

While evidence suggested attackers may have exfiltrated limited files prior to ransomware deployment, no proof emerged indicating actual or intended misuse of patient data. As a precautionary measure, Nationwide Laboratory Services advised affected individuals to monitor accounts and insurance statements for fraudulent activity. The organization provided 12 months of complimentary credit monitoring to those whose Social Security numbers were exposed. The incident occurred during a period of corporate transition, coinciding with Nationwide’s acquisition by Quest Diagnostics in summer 2021. This timing aligned with FBI warnings about ransomware groups strategically targeting companies undergoing significant financial events like mergers and acquisitions, where exfiltrated data could be leveraged to pressure victims through threats of stock price manipulation or sensitive data disclosure.

Sources
Sources available to members
1 source