Skip to content
Back to Blog
critical severity July 10, 2026 · 4 min read

ExamOne (a Quest Diagnostics Company) Data Breach Notice (Massachusetts Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

ExamOne (a Quest Diagnostics Company) notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on July 10, 2026, and the notice lists social security numbers, medical records and driver's license numbers among the information exposed.

ExamOne (a Quest Diagnostics Company) Data Breach Notice (Massachusetts Attorney General)

The filing from ExamOne, a Quest Diagnostics company, reports that the personal information of one Massachusetts resident was exposed. The categories listed are Social Security numbers, medical records, and driver's license numbers. Because these three pieces of information were named together, this single record carries unusually high long-term risk for identity theft and medical fraud.

A Social Security Number Cannot Be Replaced

When a Social Security number leaves an organisation’s control it stays valuable to criminals for the rest of the person’s life. Unlike a credit card or password, it cannot be cancelled or reissued on request. The same number that appears on tax forms, employment records, and government benefits can be used to open accounts, file fraudulent tax returns, or claim medical services in your name. That permanence is the central fact of this incident.

What the Combination of These Records Enables

A Social Security number paired with a driver’s license number is enough to create synthetic identities or to impersonate someone when applying for credit, government benefits, or employment. Adding medical records increases the danger. Those records can be sold on dark-web marketplaces to scammers who file false insurance claims, order prescription drugs, or commit medical identity theft that later appears on the victim’s Explanation of Benefits statements. Because the filing lists all three categories, anyone notified must assume the full set may have been exposed in their case.

No passwords were exposed in this incident. That is genuinely good news. There is no need to change any ExamOne or Quest Diagnostics login credentials because none were compromised. The risk lies entirely in the permanent identifiers and the sensitive health information, not in account takeover.

The Letter Is the Only Reliable Check

ExamOne is required to notify affected individuals directly, usually by mail. If you have not received a letter, your information was most likely not included in this filing. However, letters go to the last known address. Anyone who has moved since the incident should contact ExamOne directly to confirm whether their records were among those affected. The filing does not state when the incident occurred, so the letter itself remains the only practical way to know.

Why Medical Records Raise Separate Concerns

Medical records contain diagnoses, treatment histories, and insurance details that criminals can exploit in multiple ways. They can be used to file bogus claims that drive up your insurance premiums, obtain prescription medications illegally, or blackmail individuals who wish certain conditions to remain private. Because these records cannot be “reset” the way a password can, the exposure creates a lifelong privacy risk that sits alongside the identity-theft risk created by the Social Security and driver’s license numbers.

What One Record Means in a National Context

Although the Massachusetts filing names only one resident, the same organisation also appears in the breach-notification registry of other states. The small number reported here does not necessarily reflect the full scope of the incident. It simply reflects what this specific filing was required to disclose. The value of the exposed data remains high regardless of how many people ultimately received letters.

Concrete Risks That Last Years, Not Months

A stolen Social Security number combined with a driver’s license can be used to build a synthetic identity that generates debt, tax refunds, and criminal records attached to your name. Medical records add another layer: fraudulent claims can appear on your insurance history for years before they are noticed. These consequences do not expire when media coverage fades. Monitoring and protective steps must therefore be maintained long after the initial notification.

Actions That Address This Specific Exposure

  • Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name even if someone has your Social Security number and driver’s license.
  • Review every Explanation of Benefits statement from your health insurer. Look for services you did not receive. Report any suspicious claims immediately to protect both your finances and your medical history.
  • Obtain your free annual credit reports and scan them for accounts or inquiries you do not recognise. Continue checking once per year from each bureau on a rotating schedule.
  • Contact ExamOne directly if you have moved since the incident or believe you should have received a letter. Confirm whether your specific records were included.
  • Consider identity theft protection services that include dark-web monitoring for your Social Security number and medical records. The permanent nature of the exposed data makes ongoing monitoring a practical response.

This incident is small in headcount but large in consequence. One person’s Social Security number, driver’s license, and medical records are now outside the organisation’s control. Those three categories together create opportunities for identity theft and medical fraud that cannot be undone by a simple password change. The letter you may or may not have received is the only official notice you will get. Acting on the permanent identifiers now remains the most effective way to limit the damage that can unfold over the coming years.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on ExamOne (a Quest Diagnostics Company).

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  3. Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed July 10, 2026
Last reviewed July 22, 2026
Affected 1
Data exposed Social Security numbersMedical recordsDriver's license numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email