What Happened in the ACLA Data Breach?
Anatomic and Clinical Laboratory Associates, P.C., known as ACLA, is a pathology and lab testing provider serving patients in the Nashville area. The organization recently told patients that an outsider broke into its computer network and pulled sensitive files without permission. This incident is now generating attention because official notices went out to patients only a few weeks ago, even though the intrusion itself happened months earlier.
According to the notice, ACLA first spotted unusual activity on its network in December 2025. Staff immediately brought in outside cybersecurity specialists to figure out what had happened. Their work confirmed that an unauthorized party had gotten into ACLA’s systems and copied certain files before anyone noticed the intrusion.
Because the stolen files needed a careful review, the investigation stretched on for months. ACLA finished examining the affected data in April 2026, confirming that personal and health details tied to specific patients were part of what the intruder took. As a result, the company then moved to identify every patient whose records were involved so it could send proper notice.
ACLA has not shared publicly how the intruder first broke in or the exact number of systems touched. However, the company has confirmed that files were downloaded, which distinguishes this from a mere network scare with no real data loss.
Who was affected?
This breach affects patients who received lab or pathology services through ACLA. Because laboratories often work behind the scenes for other providers, some affected people may not immediately recognize the company name even though their sample or test results passed through its systems.
Based on figures associated with this incident, roughly 169,626 people in Tennessee and possibly other states may have had information involved. That is a sizable patient population for a single regional lab provider. Since lab work often includes routine screenings and specialist referrals, both adults and, potentially, minors tested through affiliated providers could be included.
What Information Was Potentially Exposed?
The categories of data ACLA says may have been accessed are unusually detailed because laboratory records combine identity information with clinical history. Not every affected person will have had every category exposed, but the notice lists a broad range of possible data points.
- Full names
- Dates of birth
- Social Security numbers
- Taxpayer identification numbers
- Medical dates of service
- Medical provider names
- Mental or physical condition information
- Medical treatment and procedure information
- Diagnosis or clinical information
- Medical history
- Patient account numbers
- Medical record numbers
This mix of data is especially concerning because it links a person’s identity directly to their health history. For example, a Social Security number paired with a diagnosis or treatment record gives a criminal far more leverage than either piece alone. Unlike a credit card number, this information cannot simply be replaced once it is out.
As a result, affected individuals face two overlapping risks. Financial identity theft can happen when criminals use Social Security or taxpayer ID numbers to open new credit lines or file fraudulent tax returns. Meanwhile, medical identity theft becomes possible when someone uses stolen health details and insurance information to receive treatment or prescriptions under another person’s name, which can even corrupt that person’s own medical file.
What is the company doing?
Once ACLA discovered the intrusion, it acted to secure its network and limit further access. The company worked with independent forensic experts throughout the investigation to understand the scope of the incident and confirm which files were involved.
After finishing its review, ACLA began mailing notification letters to potentially affected patients in June 2026. The company is also offering complimentary identity protection services through Epiq to eligible individuals. ACLA states it currently has no evidence that any exposed information has been misused, though it continues to encourage affected patients to stay alert.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Anyone notified about this incident should pull their credit reports and review them closely. Free reports are available from Equifax, Experian, and TransUnion, and checking them regularly makes it easier to spot new accounts you did not open.
Because Social Security numbers do not expire or change, this kind of monitoring should not be a one-time task. Instead, plan to check your reports periodically over the coming months, since stolen identity data can resurface long after the initial breach.
Consider a Fraud Alert or Credit Freeze
Given that Social Security and taxpayer identification numbers were potentially exposed, placing a fraud alert or a full credit freeze is a reasonable precaution. A freeze blocks most lenders from opening new credit in your name until you lift it yourself.
This step takes only a few minutes with each credit bureau but adds a meaningful layer of protection. Because freezing your credit is free and reversible, there is little downside to acting quickly rather than waiting to see if problems appear.
Watch for Medical Identity Theft
Since medical record numbers, diagnosis information, and treatment history were involved, patients should also watch their insurance statements. Explanation-of-benefits notices that list unfamiliar providers or services can be an early sign that someone is using your identity for medical care.
If anything looks unfamiliar, contact your insurer right away and ask for a written explanation. Catching medical identity theft early can prevent inaccurate information from becoming a permanent part of your health record.
Enroll in Identity Protection Services
ACLA is offering free identity protection through Epiq to eligible patients. This service typically includes monitoring for signs that your personal information is being misused elsewhere.
Enrolling costs nothing, so eligible patients should take advantage of the offer rather than let the deadline pass. Even with monitoring in place, however, you should still check your own accounts regularly rather than relying solely on an automated service.
Stay Alert for Phishing Attempts
Breach announcements like this one often trigger a wave of phishing emails and texts that reference the incident by name. Scammers may pose as ACLA, a credit bureau, or a government agency to trick worried patients into giving up more information.
Before clicking any link or replying to a message about this breach, verify it independently by contacting the company directly through a known phone number or website. If you are unsure about your legal options after receiving a notice, consulting a data breach attorney for a free case evaluation can help clarify what steps make sense for your situation.
