Company Details
quest-diagnostics
30,704
345,990
6215
questdiagnostics.com
0
QUE_1512071
In-progress

Quest Diagnostics Company CyberSecurity Posture
questdiagnostics.comQuest Diagnostics (NYSE: DGX) empowers people to take action to improve health outcomes. Derived from the world's largest database of clinical lab results, our diagnostic insights reveal new avenues to identify and treat disease, inspire healthy behaviors and improve health care management. Quest annually serves one in three adult Americans and half the physicians and hospitals in the United States, and our 47,000 employees understand that, in the right hands and with the right context, our diagnostic insights can inspire actions that transform lives. The company offers physicians the broadest test menu (3,000+ tests), is a pioneer in developing innovative new tests, is the leader in cancer diagnostics, provides anatomic pathology (AP) services, & interpretive consultation through its medical & scientific staff of about 900 M.D.s & Ph.D.s. The company reported 2020 revenues of $9.44 billion. Quest Diagnostics offers the most extensive clinical testing network in the U.S., with laboratories in most major metropolitan areas, & in Mexico, the UK & India. The company also operates four esoteric laboratories, 40 outpatient AP laboratories, & 160 smaller, rapid-response laboratories. Patients may have specimens collected in any of the company’s approximately 2,250 patient service centers. On a typical workday, testing is performed for about 550,000 patients. Quest Diagnostics empowers healthcare organizations & clinicians with state-of-the-art connectivity solutions. The company is the leading provider of pre-employment drugs-of-abuse screening for employers & risk assessment services for the life insurance industry. It is the world’s 2nd largest provider of clinical trials testing for new pharmaceuticals. More information is available at www.questdiagnostics.com. Language Assistance / Non-Discrimination Notice Asistencia de Idiomas / Aviso de no Discriminación 語言協助 / 不歧視通知 www.QuestDiagnostics.com/home/nondiscrimination
Company Details
quest-diagnostics
30,704
345,990
6215
questdiagnostics.com
0
QUE_1512071
In-progress
Between 650 and 699

Quest Diagnostics Global Score (TPRM)XXXX

Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on December 19, 2014. The breach occurred on November 17, 2014, when an employee mistakenly sent personal information via secured email to outside parties. Approximately 34,000 individuals were affected, with compromised information including names, addresses, Social Security numbers, and dates of birth.
Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on November 16, 2021. The breach occurred on October 29, 2021, due to an inadvertent email sent containing a spreadsheet with personal information of current and former employees. The information included names, Social Security Numbers, and employee ID numbers, with some individuals potentially having personal email addresses compromised.
Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on December 12, 2016. The breach occurred on November 26, 2016, when an unauthorized third party accessed the MyQuest by Care360® internet application, compromising Protected Health Information (PHI) of approximately 34,000 patients, which included names, dates of birth, and lab results.
Description: The Maine Office of the Attorney General reported a data breach involving Quest Diagnostics on October 25, 2024. The breach, which was discovered on August 27, 2024, involved inadvertent disclosure of personal information and affected a total of 1,062 individuals, including 4 residents of Maine.
Description: Quest Diagnostics suffered from a data breach that exposed 350,000 patients' protected health information. Before the attacker may have acquired or exfiltrated specific patient health information, the security team discovered the intrusion two days after the ransomware was distributed. The compromised data includes medical histories, test reports, CPT and diagnosis codes, and other data provided, as well as billing and further health data. The Quest investigated the incident and notified those affected by email.


No incidents recorded for Quest Diagnostics in 2025.
No incidents recorded for Quest Diagnostics in 2025.
No incidents recorded for Quest Diagnostics in 2025.
Quest Diagnostics cyber incidents detection timeline including parent company and subsidiaries

Quest Diagnostics (NYSE: DGX) empowers people to take action to improve health outcomes. Derived from the world's largest database of clinical lab results, our diagnostic insights reveal new avenues to identify and treat disease, inspire healthy behaviors and improve health care management. Quest annually serves one in three adult Americans and half the physicians and hospitals in the United States, and our 47,000 employees understand that, in the right hands and with the right context, our diagnostic insights can inspire actions that transform lives. The company offers physicians the broadest test menu (3,000+ tests), is a pioneer in developing innovative new tests, is the leader in cancer diagnostics, provides anatomic pathology (AP) services, & interpretive consultation through its medical & scientific staff of about 900 M.D.s & Ph.D.s. The company reported 2020 revenues of $9.44 billion. Quest Diagnostics offers the most extensive clinical testing network in the U.S., with laboratories in most major metropolitan areas, & in Mexico, the UK & India. The company also operates four esoteric laboratories, 40 outpatient AP laboratories, & 160 smaller, rapid-response laboratories. Patients may have specimens collected in any of the company’s approximately 2,250 patient service centers. On a typical workday, testing is performed for about 550,000 patients. Quest Diagnostics empowers healthcare organizations & clinicians with state-of-the-art connectivity solutions. The company is the leading provider of pre-employment drugs-of-abuse screening for employers & risk assessment services for the life insurance industry. It is the world’s 2nd largest provider of clinical trials testing for new pharmaceuticals. More information is available at www.questdiagnostics.com. Language Assistance / Non-Discrimination Notice Asistencia de Idiomas / Aviso de no Discriminación 語言協助 / 不歧視通知 www.QuestDiagnostics.com/home/nondiscrimination


Quest Diagnostics (NYSE: DGX) empowers people to take action to improve health outcomes. Derived from the world's largest database of clinical lab results, our diagnostic insights reveal new avenues to identify and treat disease, inspire healthy behaviors and improve health care management. Quest
.png)
Lawsuit filed against Quest Diagnostics for claims of violations of California's privacy laws by letting Facebook Pixel tracker collect...
Quest Diagnostics said on Wednesday it would acquire Canada-based LifeLabs from pension plan owner OMERS for about $1.35 billion, including net debt.
A Fortune 500 company has elected FedEx Corp. EVP and chief information officer Rob Carter to its board of directors. He joins Quest...
PRNewswire/ -- Quest Diagnostics (NYSE: DGX), a leading provider of diagnostic information services, today announced that its Board of...
In January, 61 data breaches of 500 or more records were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil...
Quest Diagnostics has agreed to pay almost $5 million to settle allegations it illegally dumped protected health information – and hazardous waste – at its...
These 26 Indian Chief Information Security Officers (CISOs) stand as visionary leaders, diligently shaping the future of digital defense.
Massachusetts-based ReproSource Fertility Diagnostics reached a $1.25 million settlement to resolve claims of negligence tied to a 2021 data breach.
According to local media, the lab has acknowledged a cyber attack resulting from a cybersecurity incident at a federally approved external...

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Quest Diagnostics is http://www.questdiagnostics.com.
According to Rankiteo, Quest Diagnostics’s AI-generated cybersecurity score is 673, reflecting their Weak security posture.
According to Rankiteo, Quest Diagnostics currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Quest Diagnostics is not certified under SOC 2 Type 1.
According to Rankiteo, Quest Diagnostics does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Quest Diagnostics is not listed as GDPR compliant.
According to Rankiteo, Quest Diagnostics does not currently maintain PCI DSS compliance.
According to Rankiteo, Quest Diagnostics is not compliant with HIPAA regulations.
According to Rankiteo,Quest Diagnostics is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Quest Diagnostics operates primarily in the Medical and Diagnostic Laboratories industry.
Quest Diagnostics employs approximately 30,704 people worldwide.
Quest Diagnostics presently has no subsidiaries across any sectors.
Quest Diagnostics’s official LinkedIn profile has approximately 345,990 followers.
Quest Diagnostics is classified under the NAICS code 6215, which corresponds to Medical and Diagnostic Laboratories.
No, Quest Diagnostics does not have a profile on Crunchbase.
Yes, Quest Diagnostics maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/quest-diagnostics.
As of November 28, 2025, Rankiteo reports that Quest Diagnostics has experienced 5 cybersecurity incidents.
Quest Diagnostics has an estimated 109 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Ransomware and Breach.
Detection and Response: The company detects and responds to cybersecurity incidents through an communication strategy with notified those affected by email..
Title: Quest Diagnostics Data Breach
Description: Quest Diagnostics suffered from a data breach that exposed 350,000 patients' protected health information. The security team discovered the intrusion two days after the ransomware was distributed. The compromised data includes medical histories, test reports, CPT and diagnosis codes, and other data provided, as well as billing and further health data. Quest investigated the incident and notified those affected by email.
Type: Data Breach
Attack Vector: Ransomware
Title: Quest Diagnostics Data Breach
Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on November 16, 2021. The breach occurred on October 29, 2021, due to an inadvertent email sent containing a spreadsheet with personal information of current and former employees. The information included names, Social Security Numbers, and employee ID numbers, with some individuals potentially having personal email addresses compromised.
Date Detected: 2021-10-29
Date Publicly Disclosed: 2021-11-16
Type: Data Breach
Attack Vector: Inadvertent Email
Title: Quest Diagnostics Data Breach
Description: The California Office of the Attorney General reported a data breach involving Quest Diagnostics on December 12, 2016. The breach occurred on November 26, 2016, when an unauthorized third party accessed the MyQuest by Care360® internet application, compromising Protected Health Information (PHI) of approximately 34,000 patients, which included names, dates of birth, and lab results.
Date Detected: 2016-11-26
Date Publicly Disclosed: 2016-12-12
Type: Data Breach
Attack Vector: Unauthorized Access
Threat Actor: Unauthorized Third Party
Title: Quest Diagnostics Data Breach
Description: An employee mistakenly sent personal information via secured email to outside parties.
Date Detected: 2014-11-17
Date Publicly Disclosed: 2014-12-19
Type: Data Breach
Attack Vector: Human Error
Vulnerability Exploited: Email Misconfiguration
Title: Quest Diagnostics Data Breach
Description: The Maine Office of the Attorney General reported a data breach involving Quest Diagnostics on October 25, 2024. The breach, which was discovered on August 27, 2024, involved inadvertent disclosure of personal information and affected a total of 1,062 individuals, including 4 residents of Maine.
Date Detected: 2024-08-27
Date Publicly Disclosed: 2024-10-25
Type: Data Breach
Common Attack Types: The most common types of attacks the company has faced is Breach.

Data Compromised: Medical histories, Test reports, Cpt and diagnosis codes, Billing and further health data

Data Compromised: Names, Social security numbers, Employee id numbers, Personal email addresses

Data Compromised: Names, Dates of birth, Lab results
Systems Affected: MyQuest by Care360® internet application

Data Compromised: Names, Addresses, Social security numbers, Dates of birth

Data Compromised: Personal Information
Commonly Compromised Data Types: The types of data most commonly compromised in incidents are Medical Histories, Test Reports, Cpt And Diagnosis Codes, Billing And Further Health Data, , Names, Social Security Numbers, Employee Id Numbers, Personal Email Addresses, , Protected Health Information (Phi), , Names, Addresses, Social Security Numbers, Dates Of Birth, and Personal Information.

Entity Name: Quest Diagnostics
Entity Type: Company
Industry: Healthcare
Customers Affected: 350,000

Entity Name: Quest Diagnostics
Entity Type: Company
Industry: Healthcare

Entity Name: Quest Diagnostics
Entity Type: Healthcare
Industry: Healthcare
Customers Affected: 34000

Entity Name: Quest Diagnostics
Entity Type: Healthcare
Industry: Healthcare
Customers Affected: 34000

Entity Name: Quest Diagnostics
Entity Type: Healthcare
Industry: Healthcare
Customers Affected: 1062

Communication Strategy: Notified those affected by email

Type of Data Compromised: Medical histories, Test reports, Cpt and diagnosis codes, Billing and further health data
Number of Records Exposed: 350,000

Type of Data Compromised: Names, Social security numbers, Employee id numbers, Personal email addresses
Sensitivity of Data: High
File Types Exposed: Spreadsheet

Type of Data Compromised: Protected health information (phi)
Number of Records Exposed: 34000
Sensitivity of Data: High
Personally Identifiable Information: NamesDates of Birth

Type of Data Compromised: Names, Addresses, Social security numbers, Dates of birth
Number of Records Exposed: 34000
Sensitivity of Data: High

Type of Data Compromised: Personal Information
Number of Records Exposed: 1062

Source: California Office of the Attorney General
Date Accessed: 2021-11-16

Source: California Office of the Attorney General
Date Accessed: 2016-12-12

Source: California Office of the Attorney General

Source: Maine Office of the Attorney General
Date Accessed: 2024-10-25
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: California Office of the Attorney GeneralDate Accessed: 2021-11-16, and Source: California Office of the Attorney GeneralDate Accessed: 2016-12-12, and Source: California Office of the Attorney General, and Source: Maine Office of the Attorney GeneralDate Accessed: 2024-10-25.
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through Notified those affected by email.
Last Attacking Group: The attacking group in the last incident was an Unauthorized Third Party.
Most Recent Incident Detected: The most recent incident detected was on 2021-10-29.
Most Recent Incident Publicly Disclosed: The most recent incident publicly disclosed was on 2024-10-25.
Most Significant Data Compromised: The most significant data compromised in an incident were medical histories, test reports, CPT and diagnosis codes, billing and further health data, , Names, Social Security Numbers, Employee ID Numbers, Personal Email Addresses, , Names, Dates of Birth, Lab Results, , names, addresses, Social Security numbers, dates of birth, and Personal Information.
Most Significant System Affected: The most significant system affected in an incident was MyQuest by Care360® internet application.
Most Sensitive Data Compromised: The most sensitive data compromised in a breach were Names, Lab Results, test reports, Personal Email Addresses, Dates of Birth, addresses, Personal Information, Social Security Numbers, dates of birth, CPT and diagnosis codes, Employee ID Numbers, names, medical histories, billing and further health data and Social Security numbers.
Number of Records Exposed in Most Significant Breach: The number of records exposed in the most significant breach was 350.8K.
Most Recent Source: The most recent source of information about an incident are Maine Office of the Attorney General and California Office of the Attorney General.
.png)
ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Gallery", leading to a Stored Cross-Site Scripting (XSS) vulnerability. The exploit can be triggered when any user accesses the public API endpoint of the malicious SVG images, or if the malicious images are embedded in an `iframe` element, during a widget creation, deployed to any page of the platform (e.g., dashboards), and accessed during normal operations. The vulnerability resides in the `ImageController`, which fails to restrict the execution of JavaScript code when an image is loaded by the user's browser. This vulnerability can lead to the execution of malicious code in the context of other users' sessions, potentially compromising their accounts and allowing unauthorized actions.
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects Devolutions Server: before 2025.2.21, before 2025.3.9.
Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.