Blood testing giant Quest Diagnostics lost 12,000,000 patients' personal, financial and medical data

A few years ago I was working with a client practice to integrate their EHR with Quest’s request/results interface. Once we finished setting up, we sent some test data back and forth; then my contact at Quest requested that we send some “live” patient data.

Well, I’d been entered into the EHR as a dummy patient since day 1 (with a fake SSN and dummy credit card), so we sent over a fake urinalysis for me. (No actual urine changed hands.) All the data checks passed, and we went “live”. Unfortunately, my contact at Quest forgot to set the “disregard” flag on the transaction, and it got sent to billing - where they discovered that both the credit card and SSN were dummies. The first I heard about it was a phone call from Quest’s internal collections department; fortunately, I was able to explain the situation. Oh, how we laughed and laughed.

The best part? My “results” indicated a yeast infection.

1 Like