Lab testing giant LabCorp says personal and financial info of 7.7M patients was stolen in the same data breach that affected 11.9M Quest Diagnostics patients
LabCorp is the latest laboratory testing giant this week to confirm it's affected by the same third-party data breach.
Context & Ripple Effects
This closes the loop on a shared-vendor compromise: LabCorp confirming 7.7M patients' personal and financial data stolen in the same breach that already put 11.9M Quest Diagnostics patients at risk means one third-party supplier exposed nearly 20M people across the two dominant US lab-testing companies. It is also not Quest's first exposure — its medical lab app was hacked back in 2016, exposing 34K patients' records.
First-order effects
- Roughly 19.6M patients across LabCorp and Quest now face identity and financial-fraud exposure, and both companies carry the notification, credit-monitoring, and legal costs that follow — the same post-breach liability path DNA Diagnostics Center walked into two attorney-general settlements after its own 2021 theft.
Second-order effects
- A single vendor compromise hitting both market leaders at once forces every major lab to re-audit its billing and collections suppliers, since the LifeLabs case showed attackers can extract ransom payments for data including test results — making lab-sector vendors a proven extortion target rather than a theoretical one.
Third-order effects
- The blast radius keeps widening past labs into hospitals — Ascension's notification of ~5.6M patients after its 2024 attack shows the same playbook — pointing toward consolidated liability upstream at shared service vendors and stricter contractual security demands across the healthcare supply chain.
The trend: Healthcare's most sensitive data is being harvested through shared third-party vendors, turning one compromised supplier into a multi-million-patient breach across otherwise competing providers.