Quest Diagnostics Data Breach Class Action Claims Lab Patient Information Was Exposed

Quest Diagnostics patient data was exposed in a massive third-party breach and subsequent mishandled waste disposal scandal, leaving millions vulnerable to identity theft.

Yes, Quest Diagnostics patient information was exposed in a major data breach, though the situation is more complex than a direct breach of Quest’s systems. Between August 2018 and March 2019, American Medical Collection Agency (AMCA)—a third-party billing and collection vendor handling payments for Quest Diagnostics and other major laboratory companies—fell victim to a cyberattack that exposed the personal and financial information of approximately 11.9 million Quest patients. The breach occurred without patients’ knowledge for months, only becoming public in 2019 after investigators discovered that AMCA’s systems had been compromised for nearly eight months.

The exposed data included Social Security numbers, bank account numbers, credit card information, medical information, addresses, contact details, and insurance information. However, the breach did not include actual lab test results—the clinical findings themselves remained secure. This distinction matters because while financial and identity theft risks were significant, patients’ specific diagnoses and test results were not compromised in this particular incident. AMCA’s breach ultimately became the largest healthcare data breach involving Quest, affecting roughly 11.9 million of the estimated 19 to 21 million total patients across multiple laboratory companies that used AMCA’s services.

Table of Contents

What Information Was Actually Exposed in the American Medical Collection Agency Breach?

The AMCA breach exposed multiple categories of sensitive personal information, creating compounded risk for affected patients. The compromised data included Social Security numbers, which are among the most valuable pieces of identity theft information available on criminal marketplaces. Financial account credentials—both bank account and credit card numbers—were also stolen, creating immediate fraud risk. Medical information was included, covering diagnoses, treatment histories, and other health details unrelated to Quest’s specific lab operations.

Contact information, home addresses, and insurance details rounded out the exposure, giving criminals a comprehensive profile for each victim. A practical example of the breach’s scope: A patient who had routine blood work at Quest Diagnostics and whose bill was sent through AMCA for payment might have had their Social Security number, name, address, and bank account number all stolen in a single attack. This combination allowed criminals to attempt identity theft, open fraudulent credit accounts, and conduct targeted financial fraud. Unlike a data breach that exposes only a name and email address, the AMCA breach provided nearly everything needed to impersonate a victim for financial purposes. One limitation to note: while the breadth of exposed data was extensive, Quest and AMCA did not initially disclose how much of this information was actually viewed or exfiltrated by attackers versus what was simply exposed by the security vulnerability.

How Did the Breach Happen and Who Was Really Responsible?

The breach at American Medical Collection Agency occurred over an eight-month window—from August 1, 2018, through March 30, 2019—before being detected and contained. AMCA’s systems were compromised, but the exact technical mechanisms of the breach were not fully detailed in public disclosures. What became clear was that AMCA, as a third-party vendor processing billing and collections for Quest and other major laboratory companies, had access to sensitive patient data precisely because of its role in handling payments. When AMCA’s security failed, millions of patients’ information became vulnerable even though Quest’s own laboratory information systems were not directly penetrated.

This vendor relationship is a critical warning sign for understanding healthcare data breaches: patients often have no direct relationship with or visibility into the companies handling their billing, yet these companies have access to all personal identifiers and financial information. AMCA was not the laboratory—patients never interacted with AMCA—yet AMCA possessed nearly every piece of identifiable information. The responsibility question became complex: Quest Diagnostics used AMCA as a vendor, raising questions about vendor oversight and security requirements. AMCA settled with 41 state attorneys general in March 2021 for $21 million, addressing the breach and establishing obligations for future data security and notification practices. However, individual state settlements and broader litigation against Quest and other companies continued, suggesting that questions about Quest’s responsibility for vendor selection and oversight remained contested.

Quest Diagnostics and Vendor Data Exposure TimelineAMCA Breach (2018-2019)11900000 patients affectedCalifornia Settlement (2024)5000000 patients affectedReproSource Attack (2024)350000 patients affectedClass Action Pending19000000 patients affectedSource: ITRC, California AG Settlement, SC Media, BleepingComputer

What Compensation and Settlements Have Been Available to Quest Breach Victims?

The AMCA breach resulted in a $21 million settlement with state attorneys general, announced on March 11, 2021, representing an agreement with 41 states. While this settlement was substantial, it went primarily to state coffers and funding for state attorneys general enforcement efforts rather than direct payments to individual victims. Individual class action lawsuits against Quest Diagnostics and other defendants continued, but as of June 2025, no specific settlement amount for the Quest/AMCA portion has been publicly finalized and announced, leaving many victims without compensation despite the breach’s severity.

Separately, in February 2024, California’s Attorney General secured a $5 million settlement specifically from Quest Diagnostics—not for the AMCA breach itself, but for illegal disposal of hazardous waste and unredacted patient health information. This California settlement is notable because it addresses a different Quest failure: the company had disposed of hundreds of containers of medical waste (including specimen containers with blood and urine samples), hazardous chemicals like bleach and reagents, and unredacted patient records in dumpsters where they could be accessed by the public. This demonstrates that beyond the AMCA breach, Quest faced direct violations of medical waste and data disposal regulations. The California settlement requires Quest to maintain compliance programs and submit to annual third-party audits for the next several years.

What Are Your Rights and Options If Your Data Was Exposed?

If your information was exposed in the AMCA breach affecting Quest Diagnostics patients, you have several potential paths. First, you should verify whether you were affected by checking notices sent in 2019 (AMCA and Quest mailed notifications to known addresses) or by reviewing any class action notices you may have received. Second, you have the option to file a claim in the ongoing class action litigation if a settlement is eventually reached and announced.

This requires monitoring legal tracking resources or contacting class action attorneys who are managing cases against Quest and Optum360 (another vendor involved in Quest’s revenue cycle management). A critical tradeoff exists between waiting for a potential class settlement versus pursuing individual recovery: class action settlements typically provide smaller per-person payouts (often ranging from $25 to a few hundred dollars per person) but require no individual legal action, while individual lawsuits are expensive and time-consuming but could theoretically recover more. Most victims in healthcare breaches choose the class action route simply because litigation is cost-prohibitive otherwise. Additionally, you should consider placing a fraud alert on your credit file with the three major credit bureaus (Equifax, Experian, TransUnion) or obtaining a credit freeze to prevent unauthorized accounts from being opened in your name—these protective steps are free and far more effective than waiting for compensation.

Beyond AMCA: Additional Quest Diagnostics Data Security Incidents

The AMCA breach was not Quest Diagnostics’ only significant data security incident. In August 2024, approximately 350,000 patients were affected by a ransomware attack on ReproSource Fertility Diagnostics, which is owned by Quest Diagnostics as a subsidiary. The attack occurred when a threat actor gained access to ReproSource’s systems on August 8, 2024, and ransomware was deployed two days later on August 10, 2024. ReproSource contained the attack within hours, but the breach exposed names, dates of birth, CPT and diagnosis codes, test results, medical histories, insurance information, and billing data.

The ReproSource incident illustrates an ongoing challenge for large laboratory companies: they operate multiple subsidiaries and business lines, each representing a potential attack surface. A patient might think they’re using “Quest Diagnostics” but could actually be interacting with a Quest-owned subsidiary like ReproSource, and the security practices may differ. The ReproSource ransomware attack, while less severe in terms of total patients affected than the AMCA breach, demonstrates that Quest-affiliated entities continue to face sophisticated cybersecurity threats. The timeline from initial compromise to ransomware deployment (just two days) suggests that threat actors move quickly through compromised systems, making early detection critical.

The California Waste Disposal and Medical Records Scandal

In addition to the AMCA data breach, Quest Diagnostics faced a separate but related crisis involving the improper disposal of medical waste and patient records. Inspections in California discovered that Quest had disposed of hundreds of containers containing hazardous chemicals (bleach, reagents used in lab testing), electronic waste, specimen containers with blood and urine samples, and most significantly, unredacted patient health records in dumpsters. These materials were discoverable and accessible to the public, creating both environmental hazards and serious patient privacy violations.

The $5 million settlement reached in February 2024 with California’s Attorney General addressed these violations and imposed ongoing compliance requirements. Quest must now maintain data security and medical waste disposal compliance programs and submit to annual third-party audits. This scandal revealed that Quest’s data protection failures extended beyond cybersecurity to encompass basic physical security and waste management practices—fundamental operational controls that should be routine in any healthcare organization.

The Ongoing Class Action Status and Unresolved Claims

As of June 2025, the class action litigation in the case titled “In re: American Medical Collection Agency, Inc. Customer Data Security Breach Litig.” (No. 19-md-02904, D.N.J.) remains active. Multiple class action lawsuits continue against Quest Diagnostics and Optum360, which serves as Quest’s revenue cycle management provider.

However, despite years of litigation, no final settlement amount specifically for the Quest/Optum portion of the class action has been publicly announced or finalized. This extended timeline is not unusual for complex healthcare data breach litigation involving millions of victims and multiple defendants, but it means that many affected patients remain in a state of uncertainty about potential compensation. The lack of a finalized settlement creates practical challenges for victims attempting to assess their potential recovery. Some class members may miss claim filing deadlines if a settlement is eventually announced, particularly if notification is insufficient or addresses bounce. Monitoring legal case dockets or maintaining contact with class action counsel through established case websites is essential for staying informed about developments in the litigation.


You Might Also Like

Open Settlements You Can Claim Now

Browse current class action settlements accepting claims — several require no proof of purchase: