Skip to content
Back to Blog
critical severity August 13, 2026 · 4 min read

ExamOne (a Quest Diagnostics Company) Data Breach Notice (Massachusetts Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

ExamOne (a Quest Diagnostics Company) notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on August 13, 2026, and the notice lists social security numbers, medical records and driver's license numbers among the information exposed.

ExamOne (a Quest Diagnostics Company) Data Breach Notice (Massachusetts Attorney General)

The filing from ExamOne, a Quest Diagnostics company, states that one Massachusetts resident had their Social Security number, driver's license number, and medical records exposed. Because these three categories cannot be replaced like a credit card, the exposure creates permanent risks that last for decades.

A Single Record That Combines Identity and Health Data

When a Social Security number and driver's license number leave an organisation together, they give fraudsters the two strongest building blocks needed to open accounts, file taxes, or create synthetic identities in someone else's name. Adding medical records raises the stakes further: the combination can be used to file false insurance claims, obtain prescription drugs, or blackmail the person whose history is now outside their control.

The record lists exactly these three categories. No passwords were exposed. That means the account itself was not compromised and you do not need to change any ExamOne password. The danger lies entirely in the non-revocable identifiers and the sensitive health information.

What a Social Security Number Actually Enables Long-Term

A Social Security number cannot be reissued on request the way a compromised card can. Once it is in the hands of identity thieves it retains value for years. Criminals use it to open loans, claim government benefits, or build a credit profile that later collapses on the real owner. Because this number was paired with a driver's license number, the risk of synthetic identity fraud is concrete rather than theoretical.

Medical records add another permanent layer. Health data does not expire. It can be sold on underground markets or used to impersonate you when dealing with insurers, pharmacies, or employers who run background checks that include medical history.

The Notification Gap and What It Means for You

The filing carries only the notification date of August 13, 2026. It does not state when the incident occurred. The Massachusetts Attorney General’s office requires organisations to notify affected individuals directly, usually by mail. If you have not received a letter from ExamOne, it is likely your information was not part of this single-person record. However, anyone who has moved since the incident should contact ExamOne directly to confirm whether their records were included.

Why This Exposure Matters More Than Most

Most breach notices list names and email addresses that lose value quickly. This one does not. The presence of a Social Security number, driver's license number, and medical records means the data retains high criminal utility for the rest of the person's life. Identity thieves do not need every category for every scheme; any two of these three fields are often enough to cause serious damage.

The small number of people affected—one resident according to the filing—does not reduce the severity for the individual involved. When the exposed data includes irreplaceable identifiers and protected health information, scale is secondary to impact.

Concrete Risks That Remain Open

With a Social Security number and driver's license, thieves can:

  • Apply for credit or government benefits in your name
  • File fraudulent tax returns before you do
  • Impersonate you during insurance or employment screenings

Medical records increase the chance of insurance fraud or targeted scams that reference your actual health history. These risks do not disappear after 30 or 90 days; they require ongoing vigilance.

Protecting What You Still Control

Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This stops new accounts from being opened in your name even if someone has your Social Security number. The freeze is free, reversible, and the single most effective step available.

Monitor Explanation of Benefits statements from every health insurer you use. Look for claims you did not file or services you did not receive. Medical identity theft often surfaces first through unexpected bills or denials of coverage.

Request your annual free credit reports and review them for accounts or inquiries you do not recognise. Because the Social Security number cannot be changed, early detection is the only practical defence.

Set up alerts with the major credit bureaus and with IRS account services so you are notified of any new activity tied to your identifiers. Consider identity monitoring that specifically watches for medical-related fraud in addition to financial activity.

If you receive the notification letter, follow its instructions exactly. The organisation is required to offer credit monitoring or other remedies; take advantage of them while they last.

The record establishes that one person's sensitive identifiers and health data left ExamOne's control. For that person, the exposure is lifelong. The letter is the only reliable way to know whether you are the one affected. In its absence, the strongest immediate actions are freezing credit, watching medical statements, and staying alert for unexpected financial or insurance activity that could signal misuse of the three categories named in the filing.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on ExamOne (a Quest Diagnostics Company).

  1. Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
  2. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  3. Report the licence number to your state DMV. Most states will note the number as compromised, and some will issue a new one. It is the field that turns a stolen identity into a usable one in person.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed August 13, 2026
Affected 1
Data exposed Social Security numbersMedical recordsDriver's license numbers
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email