CareNexa (Molecular Testing Labs) Data Breach: What You Need to Know

CareNexa, LLC, doing business as Molecular Testing Labs (MTL), has notified patients that a data hosting and security vendor it works with experienced a cybersecurity incident affecting MTL’s systems and data. According to the notification letter, MTL learned of the incident on or about March 11, 2025, and a subsequent forensic investigation determined the incident actually took place between March 7, 2025, and March 11, 2025. Because the intrusion happened at a vendor rather than directly inside MTL’s own systems, this is best understood as a third-party vendor breach, though the letter does not name the vendor involved.

The letter is written as an individual mailing, and while it references state-specific details like Rhode Island resident counts, the copy provided to regulators leaves those figures as unfilled placeholders. That means we cannot confirm how many people in total were affected. If you received this letter, it means MTL’s records show your personal information was included in the data reviewed after the incident.

What information was exposed?
  • The letter does not specify the exact data elements involved for your record — it uses placeholder wording instead of naming the specific information types.
  • Because MTL is offering free credit monitoring and fraud assistance, it’s reasonable to take this seriously as though sensitive identifiers (such as a Social Security number) could be involved, even though the letter itself does not confirm this.
  • As a molecular testing lab, MTL likely holds health-related and lab testing information as part of normal operations, though the letter does not confirm whether that specific category was part of this incident.

MTL is providing affected individuals with Single Bureau Credit Monitoring, Credit Report, and Credit Score services at no charge, along with proactive fraud assistance through Cyberscout, a TransUnion company. To enroll, visit https://bfs.cyberscout.com/activate and enter the unique code included in your personal copy of the letter. You must enroll within 90 days of the date on your letter, and the service requires an internet connection and email account.

What should you do now?
  • Enroll in the free credit monitoring offered by MTL as soon as possible, since the 90-day enrollment window is time-limited.
  • Watch your financial statements, insurance explanation-of-benefits notices, and credit reports closely for any activity you don’t recognize.
  • Consider placing a fraud alert or a security freeze with Equifax, Experian, and TransUnion — both are free and the freeze in particular makes it harder for anyone to open new credit in your name.
  • If you’re concerned about tax-related identity theft, consider setting up an Identity Protection PIN with the IRS at irs.gov.
  • Because the exact data exposed here isn’t fully spelled out, it may help to sign up for a service like Aura or LifeLock, which can alert you if your personal information turns up somewhere it shouldn’t.
  • Keep the letter and any confirmation of your credit monitoring enrollment in case you need to reference them later.

Leave a Comment