Centers Lab Data Breach Exposes Social Security Numbers and Medical Records

Healthcare data breach illustration
Breach Discovery: August 2025Breach Notification: July 2026

What Happened in the Centers Lab Data Breach?

Centers Lab NJ LLC, a diagnostic testing laboratory based in Hanover, New Jersey, has confirmed a major data breach affecting hundreds of thousands of patients. The company provides medical and diagnostic testing services to healthcare providers. As a result, patient data submitted by those providers ended up exposed in the incident.

According to the company, unauthorized access to its network occurred in August 2025. Suspicious activity was first identified within its computer systems on August 25, 2025. However, the forensic investigation later determined that an unauthorized third party had already gained limited access to certain systems between August 9 and August 14, 2025.

Once the suspicious activity was detected, Centers Lab isolated affected systems to contain the intrusion. In addition, the company took steps to prevent further unauthorized access. Investigators later confirmed that files containing patient information had been taken from the company’s systems by the attacker.

Because the scope of the compromised data varied by individual, Centers Lab brought in third-party data review specialists. This team performed a detailed review of the impacted files. After the review was completed, the findings were internally validated before notification letters went out to affected individuals. Notably, the Worldleaks threat group claimed responsibility for the attack and later published the stolen data on its dark web leak site, confirming that the theft was genuine and not merely suspected.

Who was affected?

The breach affects patients of the healthcare providers that use Centers Lab for diagnostic and medical testing services. Because the exposed data originated from multiple provider clients, the affected population spans numerous medical practices rather than a single office or hospital.

Centers Lab reported the breach to the HHS Office for Civil Rights as involving the protected health information of 542,377 individuals. This makes the incident one of the larger healthcare data breaches reported this year. The company has not specified the geographic distribution of affected patients, though its client base suggests a concentration in the New Jersey region and surrounding areas.

What Information Was Potentially Exposed?

The type of information exposed differs from person to person. However, Centers Lab has confirmed that a range of sensitive personal and medical details were included in the stolen files.

  • Full names
  • Dates of birth
  • Social Security numbers
  • Passport numbers
  • Driver’s license or state ID numbers
  • Medical information
  • Health insurance information

This combination of data creates significant risk for affected individuals. For example, Social Security numbers paired with names and birth dates give criminals nearly everything needed to open new credit accounts or file fraudulent tax returns. Because passport and driver’s license numbers were also exposed, victims may face a higher risk of identity document fraud as well.

Medical and health insurance information carries its own distinct dangers. Criminals can use this data to commit medical identity theft, such as submitting fraudulent insurance claims or obtaining prescription drugs under a victim’s name. As a result, affected individuals should watch not just their credit reports but also their medical and insurance records for unusual activity.

What is the company doing?

After identifying the intrusion, Centers Lab moved quickly to contain it. The company isolated the affected systems and implemented additional security measures to prevent similar incidents going forward. It also stated that strong cybersecurity protections were already in place before the attack occurred.

Following the completion of its forensic and data review process, Centers Lab began notifying affected individuals by mail. As a precaution against data misuse, the company is offering complimentary credit monitoring and identity theft protection services. These services are available for between 12 and 24 months, depending on the individual’s circumstances.

Monitor Your Credit Reports Closely

Affected individuals should check their credit reports regularly for accounts or inquiries they don’t recognize. Because Social Security numbers were exposed, criminals could attempt to open new lines of credit using stolen identities.

You can request free credit reports from all three major credit bureaus. Reviewing these reports every few months, rather than just once, makes it easier to catch fraud early before serious damage occurs.

Consider a Fraud Alert or Credit Freeze

Given that Social Security numbers, passport numbers, and driver’s license numbers were all exposed, placing a fraud alert or credit freeze is a reasonable precaution. A fraud alert requires lenders to verify your identity before extending credit. A credit freeze goes further by blocking new credit applications entirely.

Both options are free to set up through the credit bureaus. Although a freeze requires temporarily lifting it when you apply for legitimate credit, it offers the strongest protection against new-account fraud.

Watch for Medical and Insurance Fraud

Because medical information and health insurance details were exposed, affected individuals should review any statements from their health insurer carefully. Look for services or treatments listed that you don’t recognize.

If you spot suspicious claims, contact your insurance provider immediately. Reporting the issue quickly can help prevent further fraudulent use of your health benefits and protect your medical records from becoming inaccurate.

Enroll in the Offered Identity Protection Services

Centers Lab is offering free credit monitoring and identity theft protection to those affected. Enrolling in this service gives you an added layer of monitoring beyond what you might do on your own.

Since this protection is offered at no cost for a limited time, affected individuals should take advantage of it as soon as possible. Waiting too long could mean missing the enrollment window entirely.

Stay Alert to Phishing Attempts

Because your name, birth date, and other personal details were exposed, scammers may use this information to craft convincing phishing emails, texts, or phone calls. Be cautious of any unexpected messages asking you to verify personal information or click a link.

Instead, verify any suspicious communication directly with the company involved using a phone number or website you know to be legitimate. If you believe you were affected by this breach, consulting a data breach attorney can help you understand your legal options and whether you qualify for compensation.



More Information

Official data breach notification from California Attorney General

Related Data Breaches