Quest Diagnostics Company Cyber Security Posture

questdiagnostics.com

Quest Diagnostics (NYSE: DGX) empowers people to take action to improve health outcomes. Derived from the world's largest database of clinical lab results, our diagnostic insights reveal new avenues to identify and treat disease, inspire healthy behaviors and improve health care management. Quest annually serves one in three adult Americans and half the physicians and hospitals in the United States, and our 47,000 employees understand that, in the right hands and with the right context, our diagnostic insights can inspire actions that transform lives. The company offers physicians the broadest test menu (3,000+ tests), is a pioneer in developing innovative new tests, is the leader in cancer diagnostics, provides anatomic pathology (AP) services, & interpretive consultation through its medical & scientific staff of about 900 M.D.s & Ph.D.s. The company reported 2020 revenues of $9.44 billion. Quest Diagnostics offers the most extensive clinical testing network in the U.S., with laboratories in most major metropolitan areas, & in Mexico, the UK & India. The company also operates four esoteric laboratories, 40 outpatient AP laboratories, & 160 smaller, rapid-response laboratories. Patients may have specimens collected in any of the companyโ€™s approximately 2,250 patient service centers. On a typical workday, testing is performed for about 550,000 patients. Quest Diagnostics empowers healthcare organizations & clinicians with state-of-the-art connectivity solutions. The company is the leading provider of pre-employment drugs-of-abuse screening for employers & risk assessment services for the life insurance industry. It is the worldโ€™s 2nd largest provider of clinical trials testing for new pharmaceuticals. More information is available at www.questdiagnostics.com. Language Assistance / Non-Discrimination Notice Asistencia de Idiomas / Aviso de no Discriminaciรณn ่ชž่จ€ๅ”ๅŠฉ / ไธๆญง่ฆ–้€š็Ÿฅ www.QuestDiagnostics.com/home/nondiscrimination

Quest Diagnostics Company Details

Linkedin ID:

quest-diagnostics

Employees number:

30143 employees

Number of followers:

332292.0

NAICS:

621

Industry Type:

Medical and Diagnostic Laboratories

Homepage:

questdiagnostics.com

IP Addresses:

Scan still pending

Company ID:

QUE_1512071

Scan Status:

In-progress

AI scoreQuest Diagnostics Risk Score (AI oriented)

Between 900 and 1000

This score is AI-generated and less favored by cyber insurers, who prefer the TPRM score.

globalscoreQuest Diagnostics Global Score
blurone
Ailogo

Quest Diagnostics Company Scoring based on AI Models

Model NameDateDescriptionCurrent Score DifferenceScore
AVERAGE-Industry03-12-2025

This score represents the average cybersecurity rating of companies already scanned within the same industry. It provides a benchmark to compare an individual company's security posture against its industry peers.

N/A

Between 900 and 1000

Quest Diagnostics Company Cyber Security News & History

Past Incidents
5
Attack Types
2
EntityTypeSeverityImpactSeenUrl IDDetailsView
Quest DiagnosticsBreach60310/2021QUE049072425Link
Rankiteo Explanation :
Attack with significant impact with internal employee data leaks

Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on November 16, 2021. The breach occurred on October 29, 2021, due to an inadvertent email sent containing a spreadsheet with personal information of current and former employees. The information included names, Social Security Numbers, and employee ID numbers, with some individuals potentially having personal email addresses compromised.

Quest DiagnosticsBreach85411/2016QUE238072625Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on December 12, 2016. The breach occurred on November 26, 2016, when an unauthorized third party accessed the MyQuest by Care360ยฎ internet application, compromising Protected Health Information (PHI) of approximately 34,000 patients, which included names, dates of birth, and lab results.

Quest DiagnosticsBreach60411/2014QUE523072725Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on December 19, 2014. The breach occurred on November 17, 2014, when an employee mistakenly sent personal information via secured email to outside parties. Approximately 34,000 individuals were affected, with compromised information including names, addresses, Social Security numbers, and dates of birth.

Quest Diagnostics, IncorporatedBreach8548/2024QUE257072725Link
Rankiteo Explanation :
Attack with significant impact with customers data leaks

Description: The Maine Office of the Attorney General reported a data breach involving Quest Diagnostics on October 25, 2024. The breach, which was discovered on August 27, 2024, involved inadvertent disclosure of personal information and affected a total of 1,062 individuals, including 4 residents of Maine.

Quest DiagnosticsRansomware100511/2021QUE93731122Link
Rankiteo Explanation :
Attack threatening the organization's existence

Description: Quest Diagnostics suffered from a data breach that exposed 350,000 patients' protected health information. Before the attacker may have acquired or exfiltrated specific patient health information, the security team discovered the intrusion two days after the ransomware was distributed. The compromised data includes medical histories, test reports, CPT and diagnosis codes, and other data provided, as well as billing and further health data. The Quest investigated the incident and notified those affected by email.

Quest Diagnostics Company Subsidiaries

SubsidiaryImage

Quest Diagnostics (NYSE: DGX) empowers people to take action to improve health outcomes. Derived from the world's largest database of clinical lab results, our diagnostic insights reveal new avenues to identify and treat disease, inspire healthy behaviors and improve health care management. Quest annually serves one in three adult Americans and half the physicians and hospitals in the United States, and our 47,000 employees understand that, in the right hands and with the right context, our diagnostic insights can inspire actions that transform lives. The company offers physicians the broadest test menu (3,000+ tests), is a pioneer in developing innovative new tests, is the leader in cancer diagnostics, provides anatomic pathology (AP) services, & interpretive consultation through its medical & scientific staff of about 900 M.D.s & Ph.D.s. The company reported 2020 revenues of $9.44 billion. Quest Diagnostics offers the most extensive clinical testing network in the U.S., with laboratories in most major metropolitan areas, & in Mexico, the UK & India. The company also operates four esoteric laboratories, 40 outpatient AP laboratories, & 160 smaller, rapid-response laboratories. Patients may have specimens collected in any of the companyโ€™s approximately 2,250 patient service centers. On a typical workday, testing is performed for about 550,000 patients. Quest Diagnostics empowers healthcare organizations & clinicians with state-of-the-art connectivity solutions. The company is the leading provider of pre-employment drugs-of-abuse screening for employers & risk assessment services for the life insurance industry. It is the worldโ€™s 2nd largest provider of clinical trials testing for new pharmaceuticals. More information is available at www.questdiagnostics.com. Language Assistance / Non-Discrimination Notice Asistencia de Idiomas / Aviso de no Discriminaciรณn ่ชž่จ€ๅ”ๅŠฉ / ไธๆญง่ฆ–้€š็Ÿฅ www.QuestDiagnostics.com/home/nondiscrimination

Loading...

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=quest-diagnostics' -H 'apikey: YOUR_API_KEY_HERE'
newsone

Quest Diagnostics Cyber Security News

2019-06-03T07:00:00.000Z
Quest Diagnostics breach may have exposed data of 11.9M patients

Medical testing company Quest Diagnostics says 11.9 million customers may have had their medical and financial information compromised due to aย ...

2025-01-31T08:00:00.000Z
The top deals to know this week

Healthcare companies are closing out January 2025 with plenty of deals. Here's a look at the top healthcare deals this week.

2019-06-11T07:00:00.000Z
Third Party Data Breach Hits Quest Diagnostics with 12 Million Confidential Patient Records Exposed

Supply chain security vulnerabilities strike again as Fortune 500 healthcare company Quest Diagnostics appears to have left the records of itsย ...

2019-06-04T07:00:00.000Z
Nearly 12 million Quest Diagnostics patients affected by data breach

Quest Diagnostics has announced that a third-party billing collections company has been hit by a data breach, affecting 11.9 million ofย ...

2019-06-10T07:00:00.000Z
Quest, LabCorp breach stirs questions of cybersecurity risk from outside vendors

The cybersecurity data breach that hit Quest Diagnostics and LabCorp last week, which originated with billing collection vendor American Medicalย ...

2019-06-03T07:00:00.000Z
Quest Diagnostics says 11.9 million patients' financial and medical information may have been exposed in data breach

Quest Diagnostics says a data breach may have exposed the information of 11.9 million patients. American Medical Collection Agency,ย ...

2019-06-04T07:00:00.000Z
AMCA Data Breach Impacts 12 Million Quest Diagnostics Patients

A hacker has gained access to the systems of Elmsford, NY-based billing collections company American Medical Collection Agency (AMCA) andย ...

2016-12-13T08:00:00.000Z
Hacker steals data on 34,000 patients in Quest Diagnostics data breach

34,000 patients had sensitive medical data stolen from Quest Diagnostics who say "the risk of harm to patients is low.

2019-05-06T07:00:00.000Z
Top Cyber Security Breaches So Far | Cyber Security Hub

Cyber Security Hub provides readers with a notable 'Incident Of The Week.' The analysis is loaded with best practices and tips on incidentย ...

similarCompanies

Quest Diagnostics Similar Companies

Quest Diagnostics

Quest Diagnostics (NYSE: DGX) empowers people to take action to improve health outcomes. Derived from the world's largest database of clinical lab results, our diagnostic insights reveal new avenues to identify and treat disease, inspire healthy behaviors and improve health care management. Quest

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Quest Diagnostics CyberSecurity History Information

How many cyber incidents has Quest Diagnostics faced?

Total Incidents: According to Rankiteo, Quest Diagnostics has faced 5 incidents in the past.

What types of cybersecurity incidents have occurred at Quest Diagnostics?

Incident Types: The types of cybersecurity incidents that have occurred include Breach and Ransomware.

How does Quest Diagnostics detect and respond to cybersecurity incidents?

Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notified those affected by email.

Incident Details

Can you provide details on each incident?

Incident : Data Breach

Title: Quest Diagnostics Data Breach

Description: The Maine Office of the Attorney General reported a data breach involving Quest Diagnostics on October 25, 2024. The breach, which was discovered on August 27, 2024, involved inadvertent disclosure of personal information and affected a total of 1,062 individuals, including 4 residents of Maine.

Date Detected: 2024-08-27

Date Publicly Disclosed: 2024-10-25

Type: Data Breach

Incident : Data Breach

Title: Quest Diagnostics Data Breach

Description: An employee mistakenly sent personal information via secured email to outside parties.

Date Detected: 2014-11-17

Date Publicly Disclosed: 2014-12-19

Type: Data Breach

Attack Vector: Human Error

Vulnerability Exploited: Email Misconfiguration

Incident : Data Breach

Title: Quest Diagnostics Data Breach

Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on December 12, 2016. The breach occurred on November 26, 2016, when an unauthorized third party accessed the MyQuest by Care360ยฎ internet application, compromising Protected Health Information (PHI) of approximately 34,000 patients, which included names, dates of birth, and lab results.

Date Detected: 2016-11-26

Date Publicly Disclosed: 2016-12-12

Type: Data Breach

Attack Vector: Unauthorized Access

Threat Actor: Unauthorized Third Party

Incident : Data Breach

Title: Quest Diagnostics Data Breach

Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on November 16, 2021. The breach occurred on October 29, 2021, due to an inadvertent email sent containing a spreadsheet with personal information of current and former employees. The information included names, Social Security Numbers, and employee ID numbers, with some individuals potentially having personal email addresses compromised.

Date Detected: 2021-10-29

Date Publicly Disclosed: 2021-11-16

Type: Data Breach

Attack Vector: Inadvertent Email

Incident : Data Breach

Title: Quest Diagnostics Data Breach

Description: Quest Diagnostics suffered from a data breach that exposed 350,000 patients' protected health information. The security team discovered the intrusion two days after the ransomware was distributed. The compromised data includes medical histories, test reports, CPT and diagnosis codes, and other data provided, as well as billing and further health data. Quest investigated the incident and notified those affected by email.

Type: Data Breach

Attack Vector: Ransomware

What are the most common types of attacks the company has faced?

Common Attack Types: The most common types of attacks the company has faced is Breach.

Impact of the Incidents

What was the impact of each incident?

Incident : Data Breach QUE257072725

Data Compromised: Personal Information

Incident : Data Breach QUE523072725

Data Compromised: names, addresses, Social Security numbers, dates of birth

Incident : Data Breach QUE238072625

Data Compromised: Names, Dates of Birth, Lab Results

Systems Affected: MyQuest by Care360ยฎ internet application

Incident : Data Breach QUE049072425

Data Compromised: Names, Social Security Numbers, Employee ID Numbers, Personal Email Addresses

Incident : Data Breach QUE93731122

Data Compromised: medical histories, test reports, CPT and diagnosis codes, billing and further health data

What types of data are most commonly compromised in incidents?

Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Personal Information, names, addresses, Social Security numbers, dates of birth, Protected Health Information (PHI), Names, Social Security Numbers, Employee ID Numbers, Personal Email Addresses, medical histories, test reports, CPT and diagnosis codes and billing and further health data.

Which entities were affected by each incident?

Incident : Data Breach QUE257072725

Entity Type: Healthcare

Industry: Healthcare

Customers Affected: 1062

Incident : Data Breach QUE523072725

Entity Type: Healthcare

Industry: Healthcare

Customers Affected: 34000

Incident : Data Breach QUE238072625

Entity Type: Healthcare

Industry: Healthcare

Customers Affected: 34000

Incident : Data Breach QUE049072425

Entity Type: Company

Industry: Healthcare

Incident : Data Breach QUE93731122

Entity Type: Company

Industry: Healthcare

Customers Affected: 350,000

Response to the Incidents

What measures were taken in response to each incident?

Incident : Data Breach QUE93731122

Communication Strategy: Notified those affected by email

Data Breach Information

What type of data was compromised in each breach?

Incident : Data Breach QUE257072725

Type of Data Compromised: Personal Information

Number of Records Exposed: 1062

Incident : Data Breach QUE523072725

Type of Data Compromised: names, addresses, Social Security numbers, dates of birth

Number of Records Exposed: 34000

Sensitivity of Data: High

Personally Identifiable Information: True

Incident : Data Breach QUE238072625

Type of Data Compromised: Protected Health Information (PHI)

Number of Records Exposed: 34000

Sensitivity of Data: High

Personally Identifiable Information: Names, Dates of Birth

Incident : Data Breach QUE049072425

Type of Data Compromised: Names, Social Security Numbers, Employee ID Numbers, Personal Email Addresses

Sensitivity of Data: High

File Types Exposed: Spreadsheet

Personally Identifiable Information: True

Incident : Data Breach QUE93731122

Type of Data Compromised: medical histories, test reports, CPT and diagnosis codes, billing and further health data

Number of Records Exposed: 350,000

References

Where can I find more information about each incident?

Incident : Data Breach QUE257072725

Source: Maine Office of the Attorney General

Date Accessed: 2024-10-25

Incident : Data Breach QUE523072725

Source: California Office of the Attorney General

Incident : Data Breach QUE238072625

Source: California Office of the Attorney General

Date Accessed: 2016-12-12

Incident : Data Breach QUE049072425

Source: California Office of the Attorney General

Date Accessed: 2021-11-16

Where can stakeholders find additional resources on cybersecurity best practices?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: Maine Office of the Attorney GeneralDate Accessed: 2024-10-25, and Source: California Office of the Attorney General, and Source: California Office of the Attorney GeneralDate Accessed: 2016-12-12, and Source: California Office of the Attorney GeneralDate Accessed: 2021-11-16.

Investigation Status

How does the company communicate the status of incident investigations to stakeholders?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through was Notified those affected by email.

Additional Questions

General Information

Who was the attacking group in the last incident?

Last Attacking Group: The attacking group in the last incident was an Unauthorized Third Party.

Incident Details

What was the most recent incident detected?

Most Recent Incident Detected: The most recent incident detected was on 2024-08-27.

What was the most recent incident publicly disclosed?

Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-10-25.

Impact of the Incidents

What was the most significant data compromised in an incident?

Most Significant Data Compromised: The most significant data compromised in an incident were Personal Information, names, addresses, Social Security numbers, dates of birth, Names, Dates of Birth, Lab Results, Names, Social Security Numbers, Employee ID Numbers, Personal Email Addresses, medical histories, test reports, CPT and diagnosis codes and billing and further health data.

What was the most significant system affected in an incident?

Most Significant System Affected: The most significant system affected in an incident was MyQuest by Care360ยฎ internet application.

Data Breach Information

What was the most sensitive data compromised in a breach?

Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Personal Information, names, addresses, Social Security numbers, dates of birth, Names, Dates of Birth, Lab Results, Names, Social Security Numbers, Employee ID Numbers, Personal Email Addresses, medical histories, test reports, CPT and diagnosis codes and billing and further health data.

What was the number of records exposed in the most significant breach?

Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 350.8K.

References

What is the most recent source of information about an incident?

Most Recent Source: The most recent source of information about an incident are Maine Office of the Attorney General, California Office of the Attorney General, California Office of the Attorney General and California Office of the Attorney General.

What Do We Measure?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge