Labcorp to Overhaul Data Security Practices After $2.3 Million Multistate Settlement
Laboratory Corporation of America Holdings (Labcorp) has agreed to pay $2,287,455 and overhaul how it vets and manages third-party vendors, closing out a multistate investigation into the 2019 data breach at its former debt-collection vendor, American Medical Collection Agency (AMCA). The settlement, announced September 24-25, 2026 by a bipartisan coalition of 44 state attorneys general led by New York Attorney General Letitia James, is one of the largest healthcare vendor-oversight enforcement actions to date and requires Labcorp to build out a dedicated vendor risk management function, restrict how much patient data it shares with collectors, and submit to independent third-party security assessments.
Settlement Details
| Attribute | Value |
|---|---|
| Company | Labcorp (Laboratory Corporation of America Holdings) |
| Total Settlement | $2,287,455 |
| Regulators | Coalition of 44 state attorneys general, led by NY AG Letitia James |
| Underlying Incident | 2019 breach at vendor American Medical Collection Agency (AMCA) |
| Labcorp Patients Affected | 10.2 million |
| Total Individuals Affected (all AMCA clients) | 27.5 million |
| Breach Window | August 1, 2018 – March 30, 2019 |
| Data Exposed | Names, Social Security numbers, financial account data, medical test results, diagnostic codes |
| Announced | September 24-25, 2026 |
| Related Prior Settlements | $21 million AMCA settlement (2021, suspended due to bankruptcy); $35 million federal class-action settlement |
How It Happened
A Vendor Breach, Not a Direct Labcorp Intrusion
The underlying incident did not touch Labcorp's own network. AMCA, doing business under the legal name Retrieval-Masters Creditors Bureau, handled medical debt collection for Labcorp and dozens of other healthcare and laboratory clients. An intruder had unauthorized access to AMCA's payment portal and back-end systems from August 1, 2018 through March 30, 2019 — nearly eight months — before the breach was detected. Investigators found that banks processing AMCA payments had flagged suspicious activity during that window, but AMCA failed to identify or contain the intrusion until it became public.
Scale of the Exposure
Because AMCA aggregated billing and collections data across its full client roster in shared systems, the compromise cascaded well beyond Labcorp. AMCA reported that roughly 27.5 million people nationwide were affected across all client organizations, with 10.2 million of those being Labcorp patients — making it the largest healthcare-sector data breach reported in 2019 under HIPAA. Exposed data included names, Social Security numbers, financial and payment account information, and sensitive medical testing and diagnostic codes tied to lab work Labcorp had referred to AMCA for collection.
Why Regulators Targeted Labcorp, Not Just the Vendor
AMCA's exposure to liability was effectively capped by its own insolvency: the company filed for bankruptcy in the wake of remediation costs, and a 2021 multistate settlement against it produced a $21 million judgment that was suspended because AMCA could not pay. That left state attorneys general looking upstream at the healthcare companies, including Labcorp, that had entrusted AMCA with patient data in the first place. The coalition's core legal theory, echoed by Connecticut Attorney General William Tong, was that data security is a non-delegable duty — a covered entity cannot simply hand sensitive patient information to a vendor and walk away from responsibility for how it is protected. Labcorp separately agreed to a $35 million settlement in a related federal class-action lawsuit covering affected patients.
Impact Assessment
| Impact Area | Description |
|---|---|
| Regulatory Exposure | 44-state coordinated enforcement action; largest multistate healthcare vendor-oversight settlement to date |
| Financial | $2,287,455 penalty plus a separate $35 million class-action settlement; individual state shares ranged from roughly $31,000 to $89,000 |
| Operational | Labcorp must stand up a new vendor risk management team and rebuild vendor contracting and audit processes |
| Reputational | Renewed scrutiny of Labcorp's third-party risk practices, six years after the original breach became public |
| Industry-Wide | Signals to healthcare organizations and their debt collectors, billing vendors, and other data processors that regulators will pursue the data owner, not just the breached vendor |
| Patient Trust | Reinforces exposure of Social Security numbers and diagnostic data as a long-tail risk even years after remediation |
Recommendations
For Healthcare Organizations and Covered Entities
- Inventory every third-party vendor with access to patient data and classify them by sensitivity and volume of data shared.
- Minimize data shared with collections agencies, billing processors, and other vendors to only what is contractually and legally required.
- Build cybersecurity requirements — including audit rights, breach notification timelines, and data segmentation mandates — into every vendor contract, not just data processing agreements.
- Establish a standing vendor risk management function with continuous compliance monitoring rather than point-in-time due diligence at onboarding.
For Security and Risk Teams
- Require vendors handling regulated health or financial data to undergo periodic independent third-party security assessments, and retain the right to terminate immediately on failure.
- Push for data segregation clauses that prevent vendors from aggregating your organization's data alongside other clients' data in shared systems — the AMCA breach's scale was a direct result of that aggregation.
- Build an incident response plan specifically for vendor-originated security failures, including predefined escalation and notification workflows.
- Monitor for early warning signs from financial intermediaries (banks, payment processors) flagged in vendor transactions — AMCA missed exactly this signal for months.
For Patients and Consumers
- If you were a Labcorp patient in 2018-2019, monitor credit reports and consider a credit freeze given the exposure of Social Security numbers.
- Watch for phishing or fraud attempts referencing lab test results or medical debt, as diagnostic and billing data were both exposed.
- Check eligibility for any consumer restitution tied to the related $35 million class-action settlement.
Key Takeaways
- Labcorp will pay $2,287,455 to a coalition of 44 state attorneys general and implement sweeping vendor-oversight reforms tied to the 2019 AMCA breach.
- The breach originated at vendor AMCA, not Labcorp's own systems, but exposed 10.2 million Labcorp patients out of 27.5 million affected nationwide.
- Intruders had access to AMCA's systems for nearly eight months (August 2018 - March 2019) before detection, despite bank warnings of suspicious activity.
- Regulators applied a non-delegable duty theory: outsourcing data handling does not outsource legal responsibility for protecting it.
- Required reforms include a dedicated vendor risk management team, contractual audit and termination rights, data segmentation, and independent third-party security assessments.
- This settlement supplements a 2021 $21 million judgment against AMCA (suspended in bankruptcy) and a separate $35 million federal class-action settlement — underscoring the long financial tail of vendor-driven breaches.