NEWS

Labcorp to Overhaul Data Security Practices, Pay $2.3 Million Fine Over Vendor Failings

Labcorp will pay $2.3 million and overhaul vendor oversight after a 44-state settlement tied to the 2019 AMCA breach that exposed 10.2 million patients.

Dylan H.

News Desk

September 25, 2026
6 min read
Labcorp to Overhaul Data Security Practices, Pay $2.3 Million Fine Over Vendor Failings

Labcorp to Overhaul Data Security Practices After $2.3 Million Multistate Settlement

Laboratory Corporation of America Holdings (Labcorp) has agreed to pay $2,287,455 and overhaul how it vets and manages third-party vendors, closing out a multistate investigation into the 2019 data breach at its former debt-collection vendor, American Medical Collection Agency (AMCA). The settlement, announced September 24-25, 2026 by a bipartisan coalition of 44 state attorneys general led by New York Attorney General Letitia James, is one of the largest healthcare vendor-oversight enforcement actions to date and requires Labcorp to build out a dedicated vendor risk management function, restrict how much patient data it shares with collectors, and submit to independent third-party security assessments.


Settlement Details

AttributeValue
CompanyLabcorp (Laboratory Corporation of America Holdings)
Total Settlement$2,287,455
RegulatorsCoalition of 44 state attorneys general, led by NY AG Letitia James
Underlying Incident2019 breach at vendor American Medical Collection Agency (AMCA)
Labcorp Patients Affected10.2 million
Total Individuals Affected (all AMCA clients)27.5 million
Breach WindowAugust 1, 2018 – March 30, 2019
Data ExposedNames, Social Security numbers, financial account data, medical test results, diagnostic codes
AnnouncedSeptember 24-25, 2026
Related Prior Settlements$21 million AMCA settlement (2021, suspended due to bankruptcy); $35 million federal class-action settlement

How It Happened

A Vendor Breach, Not a Direct Labcorp Intrusion

The underlying incident did not touch Labcorp's own network. AMCA, doing business under the legal name Retrieval-Masters Creditors Bureau, handled medical debt collection for Labcorp and dozens of other healthcare and laboratory clients. An intruder had unauthorized access to AMCA's payment portal and back-end systems from August 1, 2018 through March 30, 2019 — nearly eight months — before the breach was detected. Investigators found that banks processing AMCA payments had flagged suspicious activity during that window, but AMCA failed to identify or contain the intrusion until it became public.

Scale of the Exposure

Because AMCA aggregated billing and collections data across its full client roster in shared systems, the compromise cascaded well beyond Labcorp. AMCA reported that roughly 27.5 million people nationwide were affected across all client organizations, with 10.2 million of those being Labcorp patients — making it the largest healthcare-sector data breach reported in 2019 under HIPAA. Exposed data included names, Social Security numbers, financial and payment account information, and sensitive medical testing and diagnostic codes tied to lab work Labcorp had referred to AMCA for collection.

Why Regulators Targeted Labcorp, Not Just the Vendor

AMCA's exposure to liability was effectively capped by its own insolvency: the company filed for bankruptcy in the wake of remediation costs, and a 2021 multistate settlement against it produced a $21 million judgment that was suspended because AMCA could not pay. That left state attorneys general looking upstream at the healthcare companies, including Labcorp, that had entrusted AMCA with patient data in the first place. The coalition's core legal theory, echoed by Connecticut Attorney General William Tong, was that data security is a non-delegable duty — a covered entity cannot simply hand sensitive patient information to a vendor and walk away from responsibility for how it is protected. Labcorp separately agreed to a $35 million settlement in a related federal class-action lawsuit covering affected patients.

Impact Assessment

Impact AreaDescription
Regulatory Exposure44-state coordinated enforcement action; largest multistate healthcare vendor-oversight settlement to date
Financial$2,287,455 penalty plus a separate $35 million class-action settlement; individual state shares ranged from roughly $31,000 to $89,000
OperationalLabcorp must stand up a new vendor risk management team and rebuild vendor contracting and audit processes
ReputationalRenewed scrutiny of Labcorp's third-party risk practices, six years after the original breach became public
Industry-WideSignals to healthcare organizations and their debt collectors, billing vendors, and other data processors that regulators will pursue the data owner, not just the breached vendor
Patient TrustReinforces exposure of Social Security numbers and diagnostic data as a long-tail risk even years after remediation

Recommendations

For Healthcare Organizations and Covered Entities

  • Inventory every third-party vendor with access to patient data and classify them by sensitivity and volume of data shared.
  • Minimize data shared with collections agencies, billing processors, and other vendors to only what is contractually and legally required.
  • Build cybersecurity requirements — including audit rights, breach notification timelines, and data segmentation mandates — into every vendor contract, not just data processing agreements.
  • Establish a standing vendor risk management function with continuous compliance monitoring rather than point-in-time due diligence at onboarding.

For Security and Risk Teams

  • Require vendors handling regulated health or financial data to undergo periodic independent third-party security assessments, and retain the right to terminate immediately on failure.
  • Push for data segregation clauses that prevent vendors from aggregating your organization's data alongside other clients' data in shared systems — the AMCA breach's scale was a direct result of that aggregation.
  • Build an incident response plan specifically for vendor-originated security failures, including predefined escalation and notification workflows.
  • Monitor for early warning signs from financial intermediaries (banks, payment processors) flagged in vendor transactions — AMCA missed exactly this signal for months.

For Patients and Consumers

  • If you were a Labcorp patient in 2018-2019, monitor credit reports and consider a credit freeze given the exposure of Social Security numbers.
  • Watch for phishing or fraud attempts referencing lab test results or medical debt, as diagnostic and billing data were both exposed.
  • Check eligibility for any consumer restitution tied to the related $35 million class-action settlement.

Key Takeaways

  1. Labcorp will pay $2,287,455 to a coalition of 44 state attorneys general and implement sweeping vendor-oversight reforms tied to the 2019 AMCA breach.
  2. The breach originated at vendor AMCA, not Labcorp's own systems, but exposed 10.2 million Labcorp patients out of 27.5 million affected nationwide.
  3. Intruders had access to AMCA's systems for nearly eight months (August 2018 - March 2019) before detection, despite bank warnings of suspicious activity.
  4. Regulators applied a non-delegable duty theory: outsourcing data handling does not outsource legal responsibility for protecting it.
  5. Required reforms include a dedicated vendor risk management team, contractual audit and termination rights, data segmentation, and independent third-party security assessments.
  6. This settlement supplements a 2021 $21 million judgment against AMCA (suspended in bankruptcy) and a separate $35 million federal class-action settlement — underscoring the long financial tail of vendor-driven breaches.

Sources