The Decatur Diagnostic Laboratory 2026 data breach was a confirmed data-exfiltration event investigated after the Alabama clinical laboratory learned of data-theft claims connected to its information. DDL's official notice says the exfiltrated data set contained personal and protected health information, and a third-party forensic review concluded on or about May 28, 2026.
The U.S. Department of Health and Human Services Office for Civil Rights lists the Decatur Diagnostic Laboratory event as a Hacking/IT Incident affecting 500 people. LeakData imported no patient or person rows, and importedRecordCount is zero. This entry relies on the official company notice, HHS record, and a reliable secondary source supporting the timeline.
How Was the DDL Breach Confirmed?
The primary source is the Notice of Data Privacy Event linked from Decatur Diagnostic Laboratory's own website. The company directly explains the data-theft claims, comprehensive forensic investigation, exfiltrated data set, verified fields, additional safeguards, and protective steps recommended to affected people.
The second confirmation is HHS OCR's breach report, which identifies DDL as a healthcare provider, classifies the event as a hacking/IT incident involving a network server, reports 500 individuals, and gives a June 16, 2026 submission date. Claim Depot adds the public April 14 data-theft claim to the chronology while linking HHS and official notices.
What Does the April 14, 2026 Date Mean?
A reliable secondary source reports that a cyberattack and data-theft claim concerning the laboratory became public on April 14. DDL's official language does not identify an attacker or access date, but it confirms learning of theft claims connected to its data and confirms that information in the event data set was exfiltrated.
The breachDate field uses April 14, 2026 as the earliest public event marker, not as a confirmed network-entry or exfiltration date. The sources do not disclose the attacker's first or last access date, entry method, or duration, so LeakData does not invent those details or make a definitive attacker attribution.
When Was the Review Completed?
DDL opened a comprehensive third-party forensic investigation and data review to determine whether sensitive information was present and to whom it related. According to the Massachusetts official consumer letter, that work concluded on or about May 28, 2026 and found that affected files may have contained personal information.
The company notified potentially affected people, contained its network, and implemented additional safeguards intended to reduce the chance of a similar event. The Massachusetts letter is dated July 13, 2026 and offers complimentary monitoring through IDX. DDL said it found no evidence of fraud or misuse, which does not mean future risk is zero.
What Personal Information May Have Been Affected?
The exfiltrated data set may contain a name together with one or more of a date of birth, driver's-license number, or Social Security number. These fields create substantial exposure to identity theft, fraudulent account opening, credit fraud, and targeted social engineering.
The official notice does not say every field was present for all 500 people; it expressly says some individuals had no information in the data set and that fields varied by person. LeakData therefore does not assume everyone's SSN or driver's-license number was involved. Passwords, payment cards, and bank accounts are not added because the source does not list them.
What Health Information Was Involved?
Possible healthcare-related fields are a patient code and medical-record number. Because DDL provides diagnostic testing and laboratory services, these identifiers are sensitive for associating a person with a laboratory record and may increase medical-identity impersonation risk.
The official notice does not list diagnoses, test results, treatment, prescriptions, health insurance, or detailed clinical histories among the affected fields. LeakData does not infer that complete laboratory results were exposed from a patient code or medical-record number. Scope stays limited to the categories explicitly named by the source.
What Should Affected People Do?
People should review financial accounts, credit reports, and health-insurance explanation-of-benefits statements for unusual activity over the next 12 to 24 months. If an unknown account, inquiry, laboratory service, or insurance claim appears, the relevant organization should be contacted through a verified channel; a fraud alert or free credit freeze may also be appropriate.
DDL published 256-355-9045 in its website notice and an IDX assistance line in individual letters. SSNs, driver's-license details, or health information should not be shared through unexpected links or calls claiming to represent the company. LeakData does not host, distribute, or make searchable the exfiltrated data set, patient codes, SSNs, or medical-record numbers.