Anatomic and Clinical Laboratory Associates, P.C. (ACLA), a pathology and laboratory services provider based in Nashville, Tennessee, has notified patients that a network security incident may have exposed their personal and health information. The company says an unknown actor gained unauthorized access to its computer network and downloaded certain files before the intrusion was discovered.
Laboratories and other healthcare providers handle some of the most sensitive information that exists about a person, and that responsibility comes with an obligation to keep it secure. When that security fails, the people whose data was exposed are the ones left to deal with the fallout.
Anatomic and Clinical Laboratory Associates, P.C.’s Data Breach Investigation
According to a notice posted by ACLA, the company became aware of potential unauthorized activity on its computer network on December 1, 2025. ACLA states that it promptly began an investigation and worked with outside cybersecurity experts to secure its systems. That investigation determined that an unknown actor had gained access to ACLA’s network and downloaded certain files without authorization. A comprehensive review of the affected files, which concluded on April 27, 2026, identified that personal and protected health information belonging to certain individuals was contained in the data that was accessed.
Healthcare and laboratory service providers have become frequent targets for cybercriminals, and it is not difficult to understand why. A single lab visit or blood draw can generate a record that ties together a patient’s name, date of birth, Social Security number, insurance and billing details, and a detailed medical history all in one place. That combination is worth far more on the black market than a stolen credit card number alone, because it cannot simply be canceled and reissued the way a card can. Once a person’s Social Security number and medical history are exposed together, that information can be reused by criminals for years.
The gap between when a breach is detected and when the public is notified is also worth understanding. Investigations like this one typically involve forensic specialists working to determine exactly which systems were accessed, which files were involved, and which specific individuals had information inside those files. Only after that painstaking review is complete can a company like ACLA identify who needs to be notified and what to tell them. In ACLA’s case, more than four months passed between the initial detection of suspicious activity and the conclusion of its review, which is a fairly typical timeline for an incident of this scope. State and federal breach notification laws generally require companies to notify affected individuals without unreasonable delay once the scope of a breach is understood, which is part of why the investigation phase can stretch on for months before letters go out.
The specific combination of data ACLA says may have been exposed, including Social Security numbers, taxpayer identification numbers, and detailed medical and treatment records, is particularly valuable to identity thieves. Social Security numbers and taxpayer identification numbers can be used to file fraudulent tax returns, open new lines of credit, or apply for loans in a victim’s name. Medical record numbers, diagnosis information, and treatment history can be used to commit medical identity theft, where a criminal uses a victim’s identity and insurance information to obtain medical services or prescription drugs, potentially leaving false information in the victim’s own medical records in the process. Because health data changes so rarely compared to a password or credit card number, it tends to remain useful to criminals for a much longer period of time.
Anyone who receives a notification letter from ACLA, or who otherwise learns their information may have been involved in this incident, should also be alert to a common follow-up risk: phishing attempts that reference the breach itself. Scammers frequently send emails or text messages posing as the breached company, a credit monitoring service, or a government agency in the weeks and months after a breach becomes public, hoping to trick anxious recipients into handing over more personal information. Anyone contacted about this incident should independently verify any communication before clicking links or providing information, rather than assuming it is legitimate simply because it references the ACLA breach.
The healthcare sector overall continues to report more breaches involving unauthorized network access than almost any other industry tracked by federal regulators, largely because medical providers and laboratories must retain detailed patient records for years while also granting network access to a wide range of staff, billing vendors, and referring providers. That combination of long data retention and broad access can make it difficult to fully close every potential entry point, even for organizations that take security seriously and respond quickly once a problem is found.
When Did This Breach Occur?
ACLA states that it first became aware of potential unauthorized activity within its computer network on December 1, 2025. The company says it immediately began an investigation, working with outside cybersecurity experts to determine what had happened and to secure its network. Following a comprehensive review of the affected data, ACLA concluded on April 27, 2026 that certain individuals’ personal and protected health information had been involved in the incident.
ACLA began mailing notification letters to potentially impacted individuals on June 23, 2026. The company has not publicly disclosed how the unauthorized access first occurred or the exact scope of the intrusion beyond confirming that files were downloaded from its network without authorization.
What Information Was Breached?
ACLA says the information that may have been involved varies by individual but can include names, dates of birth, Social Security numbers, taxpayer identification numbers, medical dates of service, medical provider names, mental or physical condition information, medical treatment and procedure information, diagnosis or clinical information, medical history, patient account numbers, and medical record numbers.
According to the sheet used to compile this report, the incident is associated with roughly 169,626 potentially affected individuals in Tennessee and elsewhere. ACLA states that it is not currently aware of any misuse of the affected information, but is offering resources to those who want to take precautions.
What You Can Do
If you received a notice from Anatomic and Clinical Laboratory Associates, P.C., or believe your information may have been affected, consider taking the following steps:
- Enroll in the complimentary identity protection services ACLA is offering through Epiq, if you are eligible.
- Review your credit reports carefully, which you can request for free from Equifax, Experian, and TransUnion.
- Consider placing a fraud alert or a security freeze on your credit files.
- Monitor your financial accounts, insurance statements, and explanation-of-benefits notices for anything unfamiliar.
- Watch for phishing emails, calls, or texts referencing this breach and avoid clicking links from unverified senders.
File a Data Breach Lawsuit Against Anatomic and Clinical Laboratory Associates, P.C.
If you were notified that your information was involved in the ACLA data breach, you may have legal options.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.