Were you recently affected by a data breach?

Anatomic and Clinical Laboratory Associates, P.C. Data Breach

Anatomic and Clinical Laboratory Associates, P.C. (ACLA), a Nashville pathology provider, discovered unauthorized network activity in December 2025. Sensitive patient data, including Social Security numbers and medical records, may have been accessed. Affected individuals were notified in June 2026 and offered free identity protection.

Anatomic and Clinical Laboratory Associates, P.C.
Date of Breach: December 1, 2025
CAU logo

Who was affected:

Clients of Anatomic and Clinical Laboratory Associates, P.C.

Impacted Data:

Names, dates of birth, Social Security numbers, taxpayer identification numbers, medical dates of service, medical provider names, mental or physical condition information, medical treatment and procedure information, diagnosis or clinical information, medical history, patient account numbers, medical record numbers

Anatomic and Clinical Laboratory Associates, P.C. (ACLA), a pathology and laboratory services provider based in Nashville, Tennessee, has notified patients that a network security incident may have exposed their personal and health information. The company says an unknown actor gained unauthorized access to its computer network and downloaded certain files before the intrusion was discovered.

Laboratories and other healthcare providers handle some of the most sensitive information that exists about a person, and that responsibility comes with an obligation to keep it secure. When that security fails, the people whose data was exposed are the ones left to deal with the fallout.

Anatomic and Clinical Laboratory Associates, P.C.’s Data Breach Investigation

According to a notice posted by ACLA, the company became aware of potential unauthorized activity on its computer network on December 1, 2025. ACLA states that it promptly began an investigation and worked with outside cybersecurity experts to secure its systems. That investigation determined that an unknown actor had gained access to ACLA’s network and downloaded certain files without authorization. A comprehensive review of the affected files, which concluded on April 27, 2026, identified that personal and protected health information belonging to certain individuals was contained in the data that was accessed.

Healthcare and laboratory service providers have become frequent targets for cybercriminals, and it is not difficult to understand why. A single lab visit or blood draw can generate a record that ties together a patient’s name, date of birth, Social Security number, insurance and billing details, and a detailed medical history all in one place. That combination is worth far more on the black market than a stolen credit card number alone, because it cannot simply be canceled and reissued the way a card can. Once a person’s Social Security number and medical history are exposed together, that information can be reused by criminals for years.

The gap between when a breach is detected and when the public is notified is also worth understanding. Investigations like this one typically involve forensic specialists working to determine exactly which systems were accessed, which files were involved, and which specific individuals had information inside those files. Only after that painstaking review is complete can a company like ACLA identify who needs to be notified and what to tell them. In ACLA’s case, more than four months passed between the initial detection of suspicious activity and the conclusion of its review, which is a fairly typical timeline for an incident of this scope. State and federal breach notification laws generally require companies to notify affected individuals without unreasonable delay once the scope of a breach is understood, which is part of why the investigation phase can stretch on for months before letters go out.

The specific combination of data ACLA says may have been exposed, including Social Security numbers, taxpayer identification numbers, and detailed medical and treatment records, is particularly valuable to identity thieves. Social Security numbers and taxpayer identification numbers can be used to file fraudulent tax returns, open new lines of credit, or apply for loans in a victim’s name. Medical record numbers, diagnosis information, and treatment history can be used to commit medical identity theft, where a criminal uses a victim’s identity and insurance information to obtain medical services or prescription drugs, potentially leaving false information in the victim’s own medical records in the process. Because health data changes so rarely compared to a password or credit card number, it tends to remain useful to criminals for a much longer period of time.

Anyone who receives a notification letter from ACLA, or who otherwise learns their information may have been involved in this incident, should also be alert to a common follow-up risk: phishing attempts that reference the breach itself. Scammers frequently send emails or text messages posing as the breached company, a credit monitoring service, or a government agency in the weeks and months after a breach becomes public, hoping to trick anxious recipients into handing over more personal information. Anyone contacted about this incident should independently verify any communication before clicking links or providing information, rather than assuming it is legitimate simply because it references the ACLA breach.

The healthcare sector overall continues to report more breaches involving unauthorized network access than almost any other industry tracked by federal regulators, largely because medical providers and laboratories must retain detailed patient records for years while also granting network access to a wide range of staff, billing vendors, and referring providers. That combination of long data retention and broad access can make it difficult to fully close every potential entry point, even for organizations that take security seriously and respond quickly once a problem is found.

When Did This Breach Occur?

ACLA states that it first became aware of potential unauthorized activity within its computer network on December 1, 2025. The company says it immediately began an investigation, working with outside cybersecurity experts to determine what had happened and to secure its network. Following a comprehensive review of the affected data, ACLA concluded on April 27, 2026 that certain individuals’ personal and protected health information had been involved in the incident.

ACLA began mailing notification letters to potentially impacted individuals on June 23, 2026. The company has not publicly disclosed how the unauthorized access first occurred or the exact scope of the intrusion beyond confirming that files were downloaded from its network without authorization.

What Information Was Breached?

ACLA says the information that may have been involved varies by individual but can include names, dates of birth, Social Security numbers, taxpayer identification numbers, medical dates of service, medical provider names, mental or physical condition information, medical treatment and procedure information, diagnosis or clinical information, medical history, patient account numbers, and medical record numbers.

According to the sheet used to compile this report, the incident is associated with roughly 169,626 potentially affected individuals in Tennessee and elsewhere. ACLA states that it is not currently aware of any misuse of the affected information, but is offering resources to those who want to take precautions.

What You Can Do

If you received a notice from Anatomic and Clinical Laboratory Associates, P.C., or believe your information may have been affected, consider taking the following steps:

  • Enroll in the complimentary identity protection services ACLA is offering through Epiq, if you are eligible.
  • Review your credit reports carefully, which you can request for free from Equifax, Experian, and TransUnion.
  • Consider placing a fraud alert or a security freeze on your credit files.
  • Monitor your financial accounts, insurance statements, and explanation-of-benefits notices for anything unfamiliar.
  • Watch for phishing emails, calls, or texts referencing this breach and avoid clicking links from unverified senders.

File a Data Breach Lawsuit Against Anatomic and Clinical Laboratory Associates, P.C.

If you were notified that your information was involved in the ACLA data breach, you may have legal options.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: July 2026 (reported)
Date of Breach: July 20, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.