Skip to content
Security & Trust

44 state AGs fine Labcorp $2.3M over a debt collector's 2019 breach

The settlement puts vendor oversight, contract terms and data minimisation at the centre of a healthcare breach case.

K
Kannan SP
· 3 min read
Share on X LinkedIn
44 state AGs fine Labcorp $2.3M over a debt collector's 2019 breach
Key finding

Labcorp customers affected by the 2019 breach: 10.2 million (Source: The Record, reporting the state attorneys general settlement (September 27, 2026))

A vendor's breach, a customer's settlement

A bipartisan coalition of 44 state attorneys general has settled a lawsuit against Labcorp. The terms are a $2.3 million fine and a commitment to broad data security reforms, according to The Record. The case concerns a 2019 breach that began at American Medical Collection Agency (AMCA), a debt collector Labcorp worked with. It affected 10.2 million Labcorp customers.

The attorneys general contended that Labcorp should have done more to police AMCA. For an organisation that shares data with outside providers, the settlement shows that 44 attorneys general were willing to pursue the data owner over a vendor's lapses, and that Labcorp agreed to pay and reform.

10.2 million
Labcorp customers affected by the 2019 breach
Source: The Record, reporting the state attorneys general settlement (September 27, 2026)
27.5 million
People affected by the AMCA incident nationwide
Source: The Record, reporting the state attorneys general settlement (September 27, 2026)
$2.3 million
Fine paid by Labcorp under the settlement
Source: The Record, reporting the state attorneys general settlement (September 27, 2026)

What Labcorp has agreed to change

The Record lists the reforms in operational terms. Labcorp will create an incident response plan for vendor security failings and limit how much data it shares with vendors. It will also build a risk management team to track vendors' compliance with data security practices.

Contract terms change as well. Labcorp must include cybersecurity requirements in vendor contracts and require data collectors to provide routine audits documenting their compliance. It must retain an independent expert to conduct information security assessments. It must also begin siloing data that debt collectors often aggregate for several clients at once.

Most of the listed measures concern vendor oversight, contracts and data sharing. The Record does not detail the scope of the independent security assessments.

The vendor's penalty and the customer's

$21 million
Fine ordered against AMCA in 2021, suspended after bankruptcy
Source: The Record, reporting the state attorneys general settlement (September 27, 2026)

In 2021, a court sided with the coalition of attorneys general suing AMCA and ordered the debt collector to pay a $21 million fine. The fine was suspended because the company went bankrupt. In this case, the settlement and the reforms fall to Labcorp, the customer that shared the data.

New York Attorney General Letitia James said in a statement: "Millions of patients' private health information was potentially exposed because of Labcorp's failures to protect its customers." A Labcorp spokesperson did not immediately respond to a request for comment, and the company did not issue a press release about the settlement, The Record reported.

What a budget-holder should ask their team

1. Which vendors hold our customers' or patients' data, and can we produce that list today? The settlement's vendor risk programme assumes the organisation knows who has its data.

2. Do our vendor contracts contain specific cybersecurity requirements, and do they require routine compliance audits? If the requirement exists only in a policy document, the contract does not enforce it.

3. For each vendor, is the data we share the minimum needed for the task? Ask specifically about vendors that aggregate data for several clients at once, since the settlement requires Labcorp to silo that data.

4. Do we have an incident response plan written for a vendor failure, as distinct from a failure on our own systems? Ask who owns it and when it was last exercised.

5. Who staffs vendor risk oversight, and does that team report on vendor compliance to the executive level? The settlement requires Labcorp to build a dedicated team for this work.

Share this insight