
Tennessee-based Anatomic and Clinical Laboratory Associates said a cyber incident last year compromised the sensitive personal information of Nearly 170,000 patients and employees.
Anatomic and Clinical Laboratory Associates is a Nashville, Tennessee-based physician-owned clinical laboratory that provides diagnostic testing and pathology services to healthcare providers.
ACLA disclosed in a data security incident notice on its website that it detected suspicious activity within its internal network on December 1. In response, the pathology center initiated an investigation with the support of external cyber security experts to assess the nature and extent of the incident, while also taking immediate measures to contain the breach, secure the impacted systems, and inform the relevant law enforcement authorities.
“Over the course of our investigation, we learned of information suggesting that an unknown actor may have gained access to our network and downloaded certain files without authorisation. Following a comprehensive review of the affected data, which concluded on April 27, 2026, ACLA learned that certain individuals’ personal and/or protected information may have been involved in this incident,” ACLA said.
The compromised data included names, dates of birth, Social Security numbers, taxpayer identification numbers, medical dates of service, medical provider names, mental or physical condition, medical treatment/procedure information, diagnosis or clinical information, medical history, patient account numbers, and medical record numbers.
The incident was reported to the U.S. Department of Health and Human Services where ACLA said it has identified at least 169,626 individuals impacted by the incident.
“ACLA has taken steps to augment security and reduce the risk of similar incidents occurring in the future,” the pathology center said.
ACLA has advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
It has also offered complimentary identity protection and credit monitoring services through Epiq to all affected individuals.
In February, the InsomniaInsomnia ransomware group claimed responsibility for the cyber attack on ACLA and listed it as a victim on its data leak site. However, neither the group nor the pathology center revealed any details on whether a ransom was paid.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543