CSIDB logo
Incident

Nationwide Laboratory Services

Incident posture

Attack window
May 2021
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-24 00:00

Linked entities

Victim
Nationwide Laboratory Services
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack encrypted files at Nationwide Laboratory Services, prompting immediate containment measures and a third-party investigation. The breach exposed protected health information, including names, dates of birth, lab results, medical and Medicare numbers, and insurance details, with Social Security numbers compromised for some individuals among the 33,437 affected. While potential data exfiltration occurred, no evidence of misuse was found, leading the organization to offer credit monitoring to those with exposed SSNs. The incident aligns with FBI warnings about ransomware groups targeting companies during significant financial events like mergers and acquisitions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On May 19, 2021, Nationwide Laboratory Services, a Boca Raton-based clinical laboratory later acquired by Quest Diagnostics, detected a ransomware attack that encrypted files across its network, blocking access to critical systems. The organization immediately implemented containment measures and engaged a third-party cybersecurity firm to investigate the breach and assist with remediation. Forensic analysis confirmed by August 31, 2021, that attackers had infiltrated network segments containing protected health information, potentially compromising data including patient names, dates of birth, lab test results, medical record numbers, Medicare identifiers, and health insurance details. A subset of affected individuals had their Social Security numbers exposed, with the specific data types varying per patient. The breach report filed with the Department of Health and Human Services’ Office for Civil Rights indicated 33,437 individuals were potentially impacted.

While evidence suggested attackers may have exfiltrated limited files prior to ransomware deployment, no proof emerged indicating actual or intended misuse of patient data. As a precautionary measure, Nationwide Laboratory Services advised affected individuals to monitor accounts and insurance statements for fraudulent activity. The organization provided 12 months of complimentary credit monitoring to those whose Social Security numbers were exposed. The incident occurred during a period of corporate transition, coinciding with Nationwide’s acquisition by Quest Diagnostics in summer 2021. This timing aligned with FBI warnings about ransomware groups strategically targeting companies undergoing significant financial events like mergers and acquisitions, where exfiltrated data could be leveraged to pressure victims through threats of stock price manipulation or sensitive data disclosure.

Sources

Sources available to members: 1 source.

CSIDB