Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

On November 26, 2016, an unauthorized third party accessed Quest Diagnostics’ MyQuest by Care360 internet application and obtained protected health information for approximately 34,000 people. Quest announced the incident on December 12, 2016. The exposed information included names, dates of birth and laboratory results, but Quest said Social Security numbers, payment-card details, insurance information and other financial information were not involved.

What happened in the Quest Diagnostics breach?

Quest said an unauthorized third party accessed its MyQuest by Care360 application on November 26, 2016. The incident involved protected health information belonging to approximately 34,000 individuals. Quest announced the breach on December 12, 2016.

In a patient letter, Quest said it became aware of the breach on November 28, 2016. The reviewed notices do not identify the attacker or explain the precise vulnerability that was exploited.

What information was exposed?

Quest’s notice said the accessed records included:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Names
  • Dates of birth
  • Laboratory results
  • Telephone numbers for some individuals

Quest said the data did not include Social Security numbers, credit-card information, insurance information or other financial information.

Were HIV test results involved?

The later settlement coverage reported a separate category for class members whose HIV test results were exposed. Those members could receive $75 under the settlement terms. This indicates that HIV test results were part of the affected records for some people; it does not mean the results of every person in the breach were exposed.

How did Quest respond, and did it report misuse?

Quest said it addressed the vulnerability after discovering the intrusion, notified affected individuals by mail, hired a cybersecurity firm to investigate and evaluate its systems, and reported the incident to law enforcement. The company described its investigation as ongoing.

In the December 2016 patient notice, Quest’s executive director of compliance operations and privacy officer, Carl A. Landorno, wrote: “Quest Diagnostics has no evidence that any information has been misused in any way, so we do not believe that you need to take any steps at this time to protect yourself in response to this breach.” That was Quest’s assessment at the time; the reviewed sources do not establish whether misuse occurred later.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened with the lawsuit and settlement?

The legal case was Morrow v. Quest Diagnostics Inc., Case No. 2:17-cv-00948-CCC-JBC, in the U.S. District Court for the District of New Jersey. Quest’s newsroom coverage reported that the court approved a $195,000 settlement on October 25, 2019.

According to that coverage, class members who could show monetary damages could collect $250, while members whose HIV test results were exposed could receive $75. These were category-based settlement terms, not a payment to every person affected by the breach.

Can affected patients still make a settlement claim?

The available settlement coverage documents court approval in 2019 but does not establish whether the claims process remains open or whether late claims are accepted. Anyone seeking to determine their eligibility should consult the official settlement notice for the case and verify any current deadlines or administrator contact details there.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How this differs from Quest’s 2019 breach

This 2016 incident involved access to the MyQuest by Care360 application and approximately 34,000 individuals. It is distinct from Quest Diagnostics’ separate 2019 American Medical Collection Agency breach, which affected millions of patients. The two incidents had different access contexts and should not be combined when describing the 2016 breach.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.