
Quest Diagnostics said Monday that a potential breach on the web payment page of its billings collection vendor exposed financial and medical information of 11.9 million patients.
The New York-based clinical laboratory provider said that, between Aug. 1, 2018 and March 30, 2019, an unauthorized user had access to the American Medical Collection Agency (AMCA) system containing information that AMC had received from Quest Diagnostics and others, according to a filing with the U.S. Securities and Exchange Commission (SEC). This information was provided to Quest by AMCA.
The information on AMCA's affected system included medical information, financial information such as credit card numbers and bank account information, and other personal information like Social Security Numbers, according to the Quest filing. Quest said its laboratory tests were not provided to AMCA, and therefore weren't impacted by the breach.
[Related: ConnectWise CEO Defends Security Stance In Wake Of Wipro Breach]
"Quest Diagnostics takes this matter very seriously and is committed to the privacy and security of patients' personal, medical and financial information," the company wrote in its filing.
The number of Quest Diagnostics patients with information on AMCA's affected system as of March 30 was approximately 11.9 million people, the company said. Quest said that AMCA has been in contact with law enforcement regarding the breach.
Quest said it has insurance coverage in place for certain potential liabilities and costs related to the breach. The insurance coverage, however, is limited in amount and subject to a deductible, according to Quest.
In response to the breach, Quest said it has stopped sending collection requests to AMCA. The company has also been working with outside security experts, AMCA and revenue cycle management provider Optum360 to investigate the AMCA breach as well as its potential impact on Quest Diagnostics and its patients.
Quest said it has provided notifications to affected public health plans, and will ensure that notification is provided to regulators and others as required by federal and state law.
related stories
Video
trending stories
sponsored resources

OutSystems
Modern Application Development 360

Symantec
Symantec Business Security Learning Center

HP Amplify™ - A Simplified Global Program for the Customer-Driven Digital Age
HP Inc.

Dell Technologies
Dell Technologies Cloud Learning Center

NPD
Industry Trends 360

EPOS
EPOS

Smart 3rd Party
3rd Party Maintenance 360

Products of the Year Showcase

Cysurance
Cyber Insurance 360

Dell Technologies
Dell Technologies Storage Learning Center

BlackBerry
BlackBerry Learning Center

Spectrum Partner Program
Spectrum Partner Program

ADT
Network Security 360

Dell Technologies
Dell Technologies Server Learning Center

WatchGuard
WatchGuard

APC by Schneider Electric
IoT Platforms 360

Tenable
Cyber Risk 360

Dell Technologies
Dell Technologies Hybrid Cloud Learning Center

StorageCraft
Disaster Recovery Learning Center

Comcast
Comcast Business Learning Center

Vertiv
Edge Computing 360

Sophos
Sophos Cybersecurity Learning Center

Wasabi
Wasabi

Webroot
Webroot Learning Center
