Comparison Overview

Quest Diagnostics

VS

Dasa

Quest Diagnostics

500 Plaza Drive, Secaucus, 07094, US
Last Update: 2026-01-21

Quest Diagnostics (NYSE: DGX) empowers people to take action to improve health outcomes. Derived from the world's largest database of clinical lab results, our diagnostic insights reveal new avenues to identify and treat disease, inspire healthy behaviors and improve health care management. Quest annually serves one in three adult Americans and half the physicians and hospitals in the United States, and our 47,000 employees understand that, in the right hands and with the right context, our diagnostic insights can inspire actions that transform lives. The company offers physicians the broadest test menu (3,000+ tests), is a pioneer in developing innovative new tests, is the leader in cancer diagnostics, provides anatomic pathology (AP) services, & interpretive consultation through its medical & scientific staff of about 900 M.D.s & Ph.D.s. The company reported 2020 revenues of $9.44 billion. Quest Diagnostics offers the most extensive clinical testing network in the U.S., with laboratories in most major metropolitan areas, & in Mexico, the UK & India. The company also operates four esoteric laboratories, 40 outpatient AP laboratories, & 160 smaller, rapid-response laboratories. Patients may have specimens collected in any of the company’s approximately 2,250 patient service centers. On a typical workday, testing is performed for about 550,000 patients. Quest Diagnostics empowers healthcare organizations & clinicians with state-of-the-art connectivity solutions. The company is the leading provider of pre-employment drugs-of-abuse screening for employers & risk assessment services for the life insurance industry. It is the world’s 2nd largest provider of clinical trials testing for new pharmaceuticals. More information is available at www.questdiagnostics.com. Language Assistance / Non-Discrimination Notice Asistencia de Idiomas / Aviso de no Discriminación 語言協助 / 不歧視通知 www.QuestDiagnostics.com/home/nondiscrimination

NAICS: 6215
NAICS Definition: Medical and Diagnostic Laboratories
Employees: 31,274
Subsidiaries: 7
12-month incidents
0
Known data breaches
4
Attack type number
2

Dasa

Av das Nações Unidas 7815, São Paulo, 05425-070, BR
Last Update: 2026-01-18

A Dasa é uma das maiores empresas de saúde do mundo, líder em medicina diagnóstica no Brasil. Trabalha para transformar sua especialização, alcance e escala em acesso à saúde de qualidade e cuidado humanizado. A empresa faz parte da vida de mais de 20 milhões de pessoas por ano, com alta tecnologia, amplo portfólio de exames e serviços e foco na melhor experiência em saúde. Com mais de 25 mil colaboradores e mais de 350 mil médicos parceiros, processa mais de 414 milhões de exames por ano em suas mais de 40 marcas presentes em todo o território nacional. Essa capilaridade única torna a Dasa a companhia de saúde que mais se relaciona com as pessoas, oferecendo soluções conectadas à realidade e à diversidade do país. Com uma governança baseada em gestão disciplinada e capacidade de execução, a empresa avança como uma organização inovadora, focada e sustentável, sempre pautada pela excelência médica e pelo compromisso com a sustentabilidade do setor da saúde.

NAICS: 6215
NAICS Definition: Medical and Diagnostic Laboratories
Employees: 31,992
Subsidiaries: 0
12-month incidents
0
Known data breaches
0
Attack type number
0

Compliance Badges Comparison

Security & Compliance Standards Overview

https://images.rankiteo.com/companyimages/quest-diagnostics.jpeg
Quest Diagnostics
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
https://images.rankiteo.com/companyimages/dasa.jpeg
Dasa
ISO 27001
ISO 27001 certification not verified
Not verified
SOC2 Type 1
SOC2 Type 1 certification not verified
Not verified
SOC2 Type 2
SOC2 Type 2 certification not verified
Not verified
GDPR
GDPR certification not verified
Not verified
PCI DSS
PCI DSS certification not verified
Not verified
HIPAA
HIPAA certification not verified
Not verified
Compliance Summary
Quest Diagnostics
100%
Compliance Rate
0/4 Standards Verified
Dasa
0%
Compliance Rate
0/4 Standards Verified

Benchmark & Cyber Underwriting Signals

Incidents vs Medical and Diagnostic Laboratories Industry Average (This Year)

No incidents recorded for Quest Diagnostics in 2026.

Incidents vs Medical and Diagnostic Laboratories Industry Average (This Year)

No incidents recorded for Dasa in 2026.

Incident History — Quest Diagnostics (X = Date, Y = Severity)

Quest Diagnostics cyber incidents detection timeline including parent company and subsidiaries

Incident History — Dasa (X = Date, Y = Severity)

Dasa cyber incidents detection timeline including parent company and subsidiaries

Notable Incidents

Last 3 Security & Risk Events by Company

https://images.rankiteo.com/companyimages/quest-diagnostics.jpeg
Quest Diagnostics
Incidents

Date Detected: 8/2024
Type:Breach
Blog: Blog

Date Detected: 11/2021
Type:Ransomware
Attack Vector: Ransomware
Blog: Blog

Date Detected: 10/2021
Type:Breach
Attack Vector: Inadvertent Email
Blog: Blog
https://images.rankiteo.com/companyimages/dasa.jpeg
Dasa
Incidents

No Incident

FAQ

Dasa company demonstrates a stronger AI Cybersecurity Score compared to Quest Diagnostics company, reflecting its advanced cybersecurity posture governance and monitoring frameworks.

Quest Diagnostics company has historically faced a number of disclosed cyber incidents, whereas Dasa company has not reported any.

In the current year, Dasa company and Quest Diagnostics company have not reported any cyber incidents.

Quest Diagnostics company has confirmed experiencing a ransomware attack, while Dasa company has not reported such incidents publicly.

Quest Diagnostics company has disclosed at least one data breach, while the other Dasa company has not reported such incidents publicly.

Neither Dasa company nor Quest Diagnostics company has reported experiencing targeted cyberattacks publicly.

Neither Quest Diagnostics company nor Dasa company has reported experiencing or disclosing vulnerabilities publicly.

Neither Quest Diagnostics nor Dasa holds any compliance certifications.

Neither company holds any compliance certifications.

Quest Diagnostics company has more subsidiaries worldwide compared to Dasa company.

Dasa company employs more people globally than Quest Diagnostics company, reflecting its scale as a Medical and Diagnostic Laboratories.

Neither Quest Diagnostics nor Dasa holds SOC 2 Type 1 certification.

Neither Quest Diagnostics nor Dasa holds SOC 2 Type 2 certification.

Neither Quest Diagnostics nor Dasa holds ISO 27001 certification.

Neither Quest Diagnostics nor Dasa holds PCI DSS certification.

Neither Quest Diagnostics nor Dasa holds HIPAA certification.

Neither Quest Diagnostics nor Dasa holds GDPR certification.

Latest Global CVEs (Not Company-Specific)

Description

Typemill is a flat-file, Markdown-based CMS designed for informational documentation websites. A reflected Cross-Site Scripting (XSS) exists in the login error view template `login.twig` of versions 2.19.1 and below. The `username` value can be echoed back without proper contextual encoding when authentication fails. An attacker can execute script in the login page context. This issue has been fixed in version 2.19.2.

Risk Information
cvss3
Base: 5.4
Severity: LOW
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Description

A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the DomainCheckerApp class within domain/script.js of Sourcecodester Domain Availability Checker v1.0. The vulnerability occurs because the application improperly handles user-supplied data in the createResultElement method by using the unsafe innerHTML property to render domain search results.

Description

A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly validate uploaded file contents. Additionally, the application preserves the user-supplied file extension during the save process. This allows an unauthenticated attacker to upload arbitrary PHP code by spoofing the MIME type as an image, leading to full system compromise.

Description

A UNIX symbolic link following issue in the jailer component in Firecracker version v1.13.1 and earlier and 1.14.0 on Linux may allow a local host user with write access to the pre-created jailer directories to overwrite arbitrary host files via a symlink attack during the initialization copy at jailer startup, if the jailer is executed with root privileges. To mitigate this issue, users should upgrade to version v1.13.2 or 1.14.1 or above.

Risk Information
cvss3
Base: 6.0
Severity: LOW
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
cvss4
Base: 6.0
Severity: LOW
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description

An information disclosure vulnerability exists in the /srvs/membersrv/getCashiers endpoint of the Aptsys gemscms backend platform thru 2025-05-28. This unauthenticated endpoint returns a list of cashier accounts, including names, email addresses, usernames, and passwords hashed using MD5. As MD5 is a broken cryptographic function, the hashes can be easily reversed using public tools, exposing user credentials in plaintext. This allows remote attackers to perform unauthorized logins and potentially gain access to sensitive POS operations or backend functions.