Centers Laboratory Discloses Data Breach Affecting 542K Individuals

Centers Lab NJ LLC, a Hanover, New Jersey-based diagnostic testing laboratory that provides medical and diagnostic testing services to healthcare providers, has announced an August 2025 cybersecurity incident affecting more than half a million patients of its healthcare provider clients.

Suspicious activity was identified within its computer systems on August 25, 2025. Systems were isolated to contain the incident, and steps were taken to prevent further unauthorized access. The forensic investigation confirmed that an unauthorized third party gained limited access to certain systems between August 9, 2025, and August 14, 2025. The forensic investigators determined that files containing patient data were exfiltrated from its systems by an unauthorized third party.

Centers Lab engaged third-party data review specialists to perform a detailed review of the impacted data, and after that process was completed, the findings were internally validated. The validation process has recently been completed, and notification letters have been mailed to the affected individuals.  The information compromised in the incident varies from individual to individual and may include names in combination with some or all of the following: date of birth, Social Security number, passport number, driver’s license number/state ID number, medical information, and health insurance information.

Centers Lab said additional data security measures have been implemented to prevent similar incidents in the future, stressing that strong cybersecurity measures had already been implemented prior to the incident. As a precaution against data misuse, the affected individuals have been offered complementary credit monitoring and identity theft protection services for between 12 and 24 months. The data breach was reported to the HHS’ Office for Civil Rights as involving the protected health information of 542,377 individuals.

While not disclosed by Centers Lab, the Worldleaks threat group claimed responsibility for the attack and published the stolen data on its dark web data leak site. The affected individuals should therefore take advantage of the free services being offered as a precaution against data misuse.

The post Centers Laboratory Discloses Data Breach Affecting 542K Individuals appeared first on The HIPAA Journal.

Free Webinar: HIPAA Compliant Email – What you Actually Need (Without an IT Team)

Small healthcare practices often assume their emails are HIPAA-compliant; however, security gaps are often found to exist that threaten patient privacy and put practices at risk of regulatory penalties. The security gaps in email are easy for small practices to miss, as they are focused on running their practices and often lack in-house IT staff with email security expertise.

Addressing these gaps is vital to ensure the privacy of patient information and compliance with the HIPAA Rules; however, implementing secure and HIPAA-compliant email systems can be technically challenging without an IT department, and secure email solutions can make accessing emails burdensome for patients.

The webinar was on August 7, 2026 but a recording is available on demand, small healthcare practices will learn how to make their emails HIPAA-compliant without an IT team, while ensuring that patients can read securely transmitted emails without first logging into a secure portal.

The 1-hour webinar will cover what HIPAA demands for email for small practices, why free Gmail and Microsoft 365 email are not sufficient for HIPAA compliance, and what to look for in an email solution when you do not have dedicated IT staff to implement and maintain it. Attendees will learn how to easily close security gaps without complex tools that your staff won’t use or portals that your patients will simply ignore.

The webinar is intended for practice owners, office managers, and administrators at mental health, dental, chiropractic, and physical therapy practices, med spas, and other small specialty practices. No technical background is needed. Click the link below to register for the webinar. If you are unable to attend on the day, register to receive a recording of the webinar that you can watch when convenient.

WEBINAR DETAILS

HIPAA Compliant Email for Small Practices – What you Actually Need (Without an IT Team)

Abailable on Demand

Click Here to Register for the Free Webinar Recording

The webinar is eligible for one self-reported Continuing Professional Education (CPE) credit. After viewing the full webinar, you will receive a certificate of attendance that may be used as supporting documentation when submitting credits to applicable certifying bodies.

Speaker: Lilly Ohno

Lilly Ohno

Lilly Ohno leads product marketing at Paubox, where she shapes how the company talks about HIPAA compliant email security to the healthcare organizations that depend on it. A USC graduate, she brings 15 years of marketing experience to the role. Paubox is a leader in HIPAA compliant email security for the healthcare industry and is trusted by more than 8,000 organizations, including Cost Plus Drugs, Rippling, and Covenant Health.

 

The post Free Webinar: HIPAA Compliant Email – What you Actually Need (Without an IT Team) appeared first on The HIPAA Journal.