Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
HIPAA ResponseBreach FilingVerified

Centers Laboratory breach filing: 542,377 individuals at a diagnostic business associate

Centers Laboratory filed a breach report with HHS OCR covering 542,377 individuals. A practice that sent orders or specimens to a breached laboratory may have notification duties of its own, depending on the arrangement.

Source of record: HHS OCRJuly 14, 2026Last verified August 22, 2026

What the source establishes

Third-party vendor relationships are among the most undermonitored surfaces in a small practice's HIPAA compliance state. A covered entity may operate with disciplined internal controls while remaining fully exposed through business associates — laboratory providers, diagnostic services, billing clearinghouses — whose security controls the practice has never formally assessed. The Centers Laboratory breach, in which an extortion group claimed 720 GB of patient data stolen affecting roughly 542,377 individuals, illustrates precisely this inherited-risk pattern: practices that transmitted orders or specimens to that vendor may carry independent notification obligations regardless of where the breach originated.

The 720 GB exfiltration volume — consistent with extended attacker dwell time before detection — underscores that bulk data staging can persist across an environment long before a covered entity or its vendors detect it.

What HIPAA requires here

45 CFR §164.308(b) (Business Associate Contracts and Other Arrangements) requires covered entities to enter into written contracts with business associates that contractually obligate those associates to implement appropriate safeguards. Separately, §164.308(a)(1) (Risk Analysis and Management) requires that third-party relationships be incorporated into the covered entity's own Security Risk Assessment. A BAA on file without a companion vendor risk review satisfies the paperwork requirement but not the risk-management requirement.

Patient Protect mapping

  • BAA Management / Vendor Risk Scanner — Patient Protect's BAA Management module maintains an auditable inventory of all executed business associate agreements, flags expiring or missing agreements, and surfaces vendors that lack documented security attestations. The Vendor Risk Scanner extends this to active third-party risk scoring.
  • Security Risk Assessment (SRA) — Patient Protect's SRA workflow prompts practices to enumerate and evaluate third-party vendors as a discrete risk domain, producing the written risk analysis documentation OCR expects when a business associate breach triggers a notification inquiry.
  • Autonomous Compliance Engine — Continuously recalculates compliance state as vendor relationships change, ensuring a new lab integration or BAA update doesn't create a silent gap.
  • Event Log — Creates an auditable record of vendor-related compliance actions — BAA reviews, risk assessments, remediation steps — that constitutes the paper trail regulators look for in a post-breach inquiry.
  • HIPAA Assistant (PIPAA) — Provides on-demand guidance on covered-entity obligations when a business associate discloses a breach, including how to evaluate whether independent patient notification is required.

Controls worth reviewing

  • Inventory every laboratory and diagnostic vendor your practice uses and confirm an executed, current BAA is on file for each — gaps here are immediately actionable.
  • Run a vendor-specific risk review within your Security Risk Assessment that documents each lab vendor's known security controls and incident history; this written record is your defense if OCR inquires.
  • Audit EHR and practice-management integration credentials issued to third-party lab systems — confirm access is scoped to minimum necessary and can be revoked immediately if a vendor is compromised.
  • Establish a breach-response checklist for business associate incidents that walks staff through the independent notification assessment your policies require.
  • Monitor the OCR breach portal for the Centers Laboratory filing; the official record will clarify data types and discovery timeline, informing your own exposure assessment.

View underlying canonical breach event →

Sources

Source of record. Centers Lab NJ LLC appears in the HHS OCR breach portal, reported July 12, 2026, affecting 542,377 individuals. Where this page and the OCR record disagree, the OCR record is correct. The filing does not publish root cause, whether data was exfiltrated, or which categories of PHI were involved; those remain unknown unless a source establishes them.

Secondary reporting. Security Week. Reporting can establish that something happened; it does not establish what was filed. Written with AI assistance under Patient Protect’s editorial standards.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →