What Happened in the Exact Sciences Breach

A data set containing 10.9 million email addresses tied to Exact Sciences, the company behind the widely used Cologuard colon cancer screening test, has been published online. The exposed records reportedly include not just email addresses but also names, physical addresses, phone numbers, and other identifying details belonging to patients, customers, and healthcare providers who interacted with the company.

Exact Sciences operates as part of Abbott Laboratories' diagnostics business, and the breach appears connected to legacy systems from that side of the company. Reports indicate the incident is being investigated alongside a separate security issue affecting Abbott, and at least one patient has already filed a lawsuit over the exposure. If this sounds familiar, it's because Abbott has faced multiple breach claims in recent months. Our coverage of Abbott's investigation into a second breach tied to its LabCentral portal shows this isn't an isolated event, but part of a pattern of incidents hitting the diagnostics and lab-testing sector.

For anyone who has ever used a Cologuard kit, scheduled a screening, or communicated with Exact Sciences by email, this breach is worth taking seriously, not because of panic, but because of what health screening data can be used for once it's in the wrong hands.

Why Health Screening Data Is a Prime Target

Medical and diagnostic data carries a different kind of value than a typical email-password leak. An email address paired with proof that someone has undergone cancer screening, along with their name, phone number, and home address, gives scammers a highly specific angle for targeted fraud.

Attackers who obtain this kind of data often run phishing campaigns disguised as messages from a healthcare provider or insurer, referencing a real test or screening to make the message feel legitimate. Because Cologuard results relate to a sensitive and emotionally charged health topic, victims may be more likely to click a link or respond urgently, especially if the message implies a follow-up on medical results.

This data can also be combined with information from other breaches, health-sector or otherwise, to build a fuller profile of a person for identity theft or insurance fraud. Unlike a password, you cannot simply reset your medical history or the fact that you took a specific screening test, which is part of why healthcare data breaches tend to have longer-lasting consequences than typical credential leaks.

How to Check if Your Email Address Was Exposed

The Exact Sciences breach data set has been indexed by breach-notification services that let you search whether your email address appears in the leak. If you've ever provided your email to Exact Sciences, whether through ordering a Cologuard kit, registering results online, or corresponding with a provider who used their systems, it's worth checking.

When you search, pay attention not just to whether your email is listed, but to what category of data was included alongside it. Breaches that expose only an email address are lower risk than those, like this one, that also include names, phone numbers, and physical addresses, since that combination is more useful to scammers running targeted campaigns.

If you're unsure whether you've ever used Exact Sciences or Cologuard services, check old emails or insurance statements for references to either name, since screenings are often billed through primary care providers rather than directly.

Six Steps to Protect Yourself This Week

  1. Search for your email in the breach. Confirm exposure before deciding how urgently to act.
  2. Watch for phishing referencing screening results. Be suspicious of any email or text claiming to be about a Cologuard test, lab result, or insurance follow-up, especially if it pressures you to click a link or call a number immediately.
  3. Change reused passwords. If you used the same password for your Exact Sciences account elsewhere, update it and enable a password manager to avoid repeats.
  4. Turn on two-factor authentication wherever your healthcare provider or insurer offers it, adding a barrier even if login credentials are exposed elsewhere.
  5. Monitor financial and medical statements. Look for unfamiliar charges or insurance claims, a common sign of medical identity theft.
  6. Use a VPN when accessing patient portals, particularly on public Wi-Fi, to reduce the chance of your login credentials or session data being intercepted while managing sensitive health accounts.

What This Means for You

The Exact Sciences data breach is a reminder that health data breaches are rarely one-off events. They tend to ripple outward, touching partner companies, legacy systems, and third-party portals long after the original test or screening took place. If your information appears in this breach, the practical risk is less about the data itself being retrieved back and more about staying alert to how it might be used against you in phishing attempts or identity fraud over the coming months.

Taking a few minutes now to check your exposure and tighten your login habits is far less costly than dealing with the aftermath of a targeted scam built around your medical history.

Key Takeaways

  • Search for your email address in the Exact Sciences breach data to confirm exposure.
  • Be extra cautious of emails or texts referencing Cologuard or screening results.
  • Update reused passwords and enable two-factor authentication on healthcare accounts.
  • Use a VPN when logging into patient portals, especially on shared or public networks.
  • Keep an eye on this story, as Abbott's broader breach investigations suggest more healthcare data incidents may surface in the coming weeks.