Tennessee Pathology Group Announces 170K-record Data Breach
Anatomic and Clinical Laboratory Associates is notifying almost 170,000 patients about a recent cybersecurity incident. Data breaches have also been announced by ZenPatient, Saint Pete MRI, Carlyle Senior Care, SportsMed Physical Therapy, and Lifeways Inc.
Anatomic and Clinical Laboratory Associates
Anatomic and Clinical Laboratory Associates, P.C., a Nashville, TN-based physician-owned pathology group, has announced a significant data breach involving the protected health information of 169,626 current and former patients.
An investigation was launched on December 1, 2025, when anomalous activity was identified within its computer network. Third-party cybersecurity experts were engaged to assist with the investigation and ensure the security of its computer systems. During the course of the investigation, unauthorized network access was confirmed. It is unclear from the breach notice when the unauthorized access occurred or for how long its network was compromised.
The review of the exposed data was completed on April 27, 2026, when it was confirmed that personal and protected health information had been exposed. The affected individuals had their names exposed, along with one or more of the following data elements: date of birth, Social Security number, taxpayer identification number, date(s) of service, medical provider name(s), mental/physical condition, medical treatment/procedure information, diagnosis or clinical information, medical history, patient account number, and/or medical record number.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Notification letters were mailed to the affected individuals on June 23, 2026, and complimentary credit monitoring and identity theft protection services have been offered to certain individuals, dictated by the types of information involved. Anatomic and Clinical Laboratory Associates have implemented additional security measures to prevent similar incidents in the future.
ZenPatient
ZenPatient, Inc., a Santa Monica, CA-based provider of telehealth and messaging software platform, has announced a cybersecurity incident that involved unauthorized access to its network between December 2025 and February 2026. Suspicious activity was identified within its computer network on February 27, 2026. Assisted by third-party cybersecurity professionals, the incident was investigated, and it was confirmed that an unauthorized third party had access to its network between December 5, 2025, and February 12, 2026, during which time certain files were exfiltrated from its network.
The compromised files were reviewed and found to contain names, addresses, birth dates, and medical information. Notification letters were sent to the affected individuals on July 17, 2026. ZenPatient said it is unaware of any misuse of patient data as a result of the incident; however, as a precaution against data misuse, complimentary credit monitoring services have been made available to the affected individuals for 12 months. Additional cybersecurity measures have been implemented to reduce the risk of similar incidents in the future. The data breach has been reported to regulators, but the number of affected individuals has yet to be publicly disclosed.
Saint Pete MRI
Saint Pete MRI, a St. Petersburg, FL-based full-service diagnostic imaging and sleep lab, is notifying certain patients about a cybersecurity incident it identified on or around February 23, 2025. Immediate action was taken to investigate the incident and secure its computer systems, and a third-party cybersecurity firm was engaged to assist with those processes.
The investigation confirmed that electronic patient care and imaging systems were not subject to unauthorized access; however, the unauthorized party behind the incident may have acquired certain scanned data. The affected files were reviewed, and on April 7, 2026, Saint Pete MRI confirmed that they contained names, dates of birth, Social Security numbers, driver’s license numbers or state identification numbers, medical information, and/or health insurance information.
Notification letters were mailed to the affected individuals on July 22, 2026, around 17 months after the incident was first identified. The incident is not currently shown on the HHS’ Office for Civil Rights data breach portal, so it is unclear how many individuals have been affected.
Carlyle Senior Care Management Company
Carlyle Senior Care Management Company, a South Carolina-based management company for Carlyle Senior Care independent living, senior living, and skilled nursing care facilities in the state, has reported a data breach to the HHS’ Office for Civil Rights involving the protected health information of 4,060 individuals.
There is currently no substitute data breach notice on the Carlyle Senior Care website, and no press release appears to have been issued, so it is unclear what data types were involved. This appears to have been a ransomware attack conducted by the Insomnia ransomware group, which claimed on its data leak site to have stolen data from Carlyle Senior Care of Florence. Insomnia claimed to have notified Carlyle Senior Care about the breach on October 31, 2025, then proceeded to leak the stolen data. Insomnia claimed to have stolen patient records, internal documents, and sensitive information.
SportsMed Physical Therapy
SportsMed Physical Therapy, a physical therapy clinic with locations in New Jersey and Connecticut, has identified unauthorized access to a single email account. The breach was identified on May 8, 2026, and the account was secured. An investigation was launched to determine the individuals affected and the types of data involved.
The review has recently been completed and confirmed that names had been compromised in combination with one or more of the following: date of service, provider name, diagnosis information, treatment information, and/or health insurance information. SportsMed Physical Therapy said it is unaware of any misuse of patient information as a result of the incident. The incident is not currently shown on the HHS’ Office for Civil Rights website, so it is currently unclear how many individuals have been affected.
Lifeways
Lifeways Inc., a nonprofit provider of mental health counseling and addiction services to patients in Idaho and Oregon, identified unauthorized access to an employee’s email account. The email account breach was identified on January 21, 2026, and after securing the account, an investigation was launched to determine the nature and scope of the unauthorized activity. The investigation revealed several employee email accounts had been compromised.
The incident was limited to its email environment. On May 8, 2026, Lifeways confirmed that the exposed information included names, birth dates, Social Security numbers, driver’s license/state identification numbers, financial account numbers, patient account numbers, medical record numbers, diagnoses, treatment and procedure information, prescription information, treatment locations, provider names, Medicare and Medicaid numbers, clinical information, and health insurance information. At the time of issuing notification letters, Lifeways was unaware of any misuse of the exposed information. The Oregon Attorney General was informed that 343 individuals have been affected.


