SYS::ONLINE
Wasteland.
Briefs1546
Issues20
SinceFeb 2026
LIVE
▣ Breach ANATOMIC-CLINICAL- 2026-07-26

Anatomic and Clinical Laboratory Associates: Unattributed Network Intrusion Exposes 169,626 Patient Records

"Anatomic and Clinical Laboratory Associates, P.C., a physician-owned pathology group based in Nashville, Tennessee, has confirmed a network intrusion that exposed the personal and protected health information of 169,626…"

Anatomic and Clinical Laboratory Associates, P.C., a physician-owned pathology group based in Nashville, Tennessee, has confirmed a network intrusion that exposed the personal and protected health information of 169,626 current and former patients. The organization detected anomalous activity on its network on December 1, 2025, engaged third-party cybersecurity experts, and confirmed unauthorized access during the subsequent investigation. Data review concluded on April 27, 2026, and notification letters went out on June 23, 2026. The breach was publicly reported by HEAL Security on July 24, 2026, alongside separate incidents disclosed by ZenPatient, Saint Pete MRI, Carlyle Senior Care, SportsMed Physical Therapy, and Lifeways Inc.

What Happened

The timeline the pathology group has disclosed is thin in the places that matter most. Anomalous activity was identified inside its computer network on December 1, 2025. External incident response specialists were brought in to investigate and to secure the environment. That investigation confirmed unauthorized third-party access to the network.

What the breach notice does not say is when the intrusion actually began or how long the attacker held access before detection. That gap is significant. In comparable healthcare incidents disclosed in the same reporting cycle, ZenPatient was able to bracket its intrusion precisely, from December 5, 2025, to February 12, 2026, and confirm file exfiltration during that window. Anatomic and Clinical Laboratory Associates has published no equivalent dwell-time bracket, no exfiltration confirmation, and no attribution.

The interval between detection and disclosure is itself notable. Detection on December 1, 2025, data review completion on April 27, 2026, and notification on June 23, 2026 amounts to roughly 205 days from detection to patient notification. Nearly five months of that was consumed by the forensic review of affected data, which is characteristic of unstructured document repositories and file shares rather than a clean, queryable database. Pathology practices sit on exactly that kind of data: scanned requisitions, signed reports, correspondence, and billing artifacts.

No ransomware group has claimed the incident in the public reporting, and the notice describes no encryption event or service disruption. Treat the absence of a claim as absence of evidence, not evidence of absence.

What Was Taken

Every affected individual had their name exposed. Beyond that, the notice describes a per-person combination drawn from an unusually broad set of elements:

This is a worst-case composition. It pairs permanent identity anchors (SSN, TIN, date of birth) with clinical detail (diagnosis, mental and physical condition, treatment history) and with the internal keys used to look a patient up across systems (medical record number, patient account number).

Pathology data carries a specificity problem that general practice records do not. A pathology group is where a diagnosis is confirmed. Records handled by this kind of practice routinely establish oncology status, infectious disease results, genetic and molecular findings, and reproductive health outcomes. The explicit inclusion of "mental/physical condition" and "diagnosis or clinical information" in the disclosed elements means the exposed set is not merely administrative metadata about care; it is the substance of the diagnosis itself.

The offer of credit monitoring and identity theft protection was extended only to "certain individuals, dictated by the types of information involved," which indicates the SSN and TIN exposure applied to a subset rather than the full 169,626. The clinical exposure has no equivalent remedy, and no monitoring product mitigates it.

Why It Matters

Specialty diagnostic providers are a structural blind spot in healthcare security. A pathology group is a small organization by headcount and IT budget, but it holds records on the entire patient population of every referring hospital, clinic, and physician practice it serves. Nearly 170,000 records from a single physician-owned Nashville practice illustrates the leverage: the attacker does not need to breach the health system to reach the health system's patients.

Three points deserve attention from defenders:

The referral network is the attack surface. Patients in this dataset overwhelmingly never chose this laboratory; their specimens were routed there. Downstream covered entities inherit the breach exposure without inheriting any control over the security posture that produced it.

Undefined dwell time is an unresolved risk, not a closed one. With no stated intrusion start date and no confirmation of whether files were exfiltrated, the organization cannot bound the loss, and neither can anyone relying on its disclosure. Detection on December 1 tells us when the attacker was noticed, not when they arrived.

Diagnosis data is coercion-grade material. Credit fraud is the recoverable harm here. The durable harm is a permanent, verifiable record linking named individuals to specific medical conditions, suitable for extortion, targeted social engineering against patients and their providers, and insurance or employment discrimination. It cannot be reissued the way an SSN can be monitored or a card can be reprinted.

The clustering in the source report matters as well. Six healthcare organizations disclosed breaches in a single reporting window, spanning telehealth software, imaging, senior care, physical therapy, and behavioral health. This is sustained, broad-based pressure on mid-market healthcare providers, not a set of isolated events.

The Attack Technique

Initial access vector has not been disclosed. The notice confirms unauthorized network access and nothing more specific: no phishing, no exploited edge device, no compromised vendor, no stolen credentials named.

What the disclosure does support is a general shape. The incident is described as unauthorized access to the internal network rather than compromise of a single application or cloud tenant, which points to a foothold with lateral reach across file storage. The five-month document review implies the attacker's reach extended to unstructured repositories where scanned reports and correspondence accumulate. Detection came from "anomalous activity identified within its computer network," suggesting behavioral or alert-based detection after the fact rather than interception at the point of entry.

Against comparable mid-market healthcare intrusions in this period, the realistic candidate vectors are internet-facing remote access and VPN appliances with unpatched vulnerabilities or absent multi-factor authentication, credential compromise through phishing or infostealer logs sold on access markets, and third-party or managed service provider access paths. Absent disclosure, none of these should be asserted as fact for this incident.

The remediation statement, that additional security measures have been implemented, is boilerplate and carries no actionable detail.

What Organizations Should Do

Concrete steps for pathology groups, reference laboratories, imaging centers, and the health systems that refer to them:

  1. Enforce phishing-resistant MFA on every remote access path. Cover VPN, remote desktop, administrative consoles, and the EHR or LIS web portals. Prioritize hardware-backed or FIDO2 authenticators over SMS and push, and audit for accounts and service principals excluded from enforcement policies. Unauthenticated or single-factor edge access remains the most common route into organizations of this size.

  2. Instrument file shares for bulk access and exfiltration detection. A five-month review to determine what was exposed usually signals that no one could tell what the attacker touched. Enable object-level and file-access auditing on repositories holding scanned reports and requisitions, alert on anomalous volume of reads by any single account, and monitor egress to cloud storage and file transfer services. This converts an unbounded investigation into a bounded one.

  3. Segment the diagnostic environment from general corporate IT. Laboratory information systems, instrument networks, and report archives should not be reachable from a compromised workstation on the business VLAN. Restrict east-west traffic by default and require explicit, logged paths between segments.

  4. Reduce the retained data footprint, particularly SSNs and TINs. Inventory where Social Security and taxpayer identification numbers are stored, and determine whether the clinical workflow requires their retention at all or only the billing workflow does. Tokenize or purge what is not operationally necessary. The presence of TINs alongside SSNs here suggests billing and clinical records are commingled in the same repositories.

  5. Extend third-party risk assessment to diagnostic and reference partners. Health systems should assess pathology, imaging, and laboratory partners with the same rigor applied to major software vendors, since a single small partner can hold the full patient roster. Require contractual breach notification timelines, and confirm partners can produce intrusion start dates and exfiltration determinations, not only detection dates.

  6. Build patient-notification and clinical-extortion response into the incident plan now. Where diagnosis and mental or physical condition data is in scope, prepare for direct extortion attempts against individual patients and for social engineering that uses accurate clinical detail as a credibility prop. Brief front-desk and clinical staff that callers may quote real medical record numbers and real diagnoses without being legitimate.

For the 169,626 individuals affected, the practical guidance is to enroll in the offered monitoring if eligible, place a credit freeze at all three bureaus regardless of eligibility, and treat any inbound contact referencing their medical history as hostile until independently verified through a known-good phone number.

Sources: Tennessee Pathology Group Announces 170K-record Data Breach - HEAL Security Inc.