Labcorp Reaches $2.3 Million Multistate Settlement Over AMCA Data Breach
Labcorp has agreed to a $2.3 million multistate settlement resolving an investigation into the 2019 data breach involving American Medical Collection Agency, a former debt collection vendor that handled information belonging to millions of Labcorp patients.
The settlement, announced by the Wisconsin Department of Justice and a coalition of state attorneys general, focuses heavily on vendor oversight and cybersecurity requirements. Labcorp will be required to strengthen controls around third-party vendors, including debt collection agencies that receive or process sensitive patient information.
The breach occurred at Retrieval-Masters Creditors Bureau, which operated as American Medical Collection Agency, or AMCA. According to the Wisconsin DOJ, the incident potentially exposed personal information belonging to more than 27.5 million people nationwide, including approximately 10.2 million Labcorp patients. Another 16,615 affected individuals were Wisconsin residents.
Settlement Places Focus on Vendor Responsibility
Although the breach occurred within AMCA’s systems, the multistate investigation focused on Labcorp’s responsibility for safeguarding patient information shared with outside vendors.
The Wisconsin DOJ said organizations may outsource services and delegate certain responsibilities, but the obligation to protect sensitive data remains with the company that controls the information.
Wisconsin Attorney General Josh Kaul said consumers should be able to expect appropriate protection of sensitive health information and said the settlement is intended to strengthen Labcorp’s safeguards against similar incidents.
The settlement reflects increased attention on vendor risk management, particularly when outside service providers handle medical, financial, or other sensitive consumer information.
New Requirements for Labcorp’s Vendor Oversight
Under the agreement, Labcorp must make several changes to its information security and vendor management programs.
The company must strengthen its incident response procedures, including processes for internally reporting cybersecurity events involving vendors. Labcorp will also be required to limit the amount of information provided to vendors where appropriate while accounting for legal and operational requirements that may apply to debt collection activities.
Its vendor risk management program must also include a dedicated team, tools for evaluating vendor security practices, and procedures for confirming compliance with security requirements.
Debt collection vendors will receive additional scrutiny under the settlement. Labcorp must maintain inventories of applicable contracts, incorporate cybersecurity requirements into those agreements, and establish processes for assessing and auditing collection vendors.
The agreement also addresses data segmentation. Debt collectors may receive information from multiple clients, creating circumstances in which large volumes of data are stored or processed within the same environment. The settlement requires controls intended to reduce risks associated with that aggregation.
Contracts must also give Labcorp the ability to terminate vendor relationships when cybersecurity requirements are not met.
Third-Party Security Assessment Required
Labcorp must hire an independent third-party assessor to evaluate its information security program, with particular attention given to vendor risk management.
The requirement adds an external review component to the settlement and is intended to measure whether the company’s vendor oversight practices are functioning as required.
Labcorp will also pay $2,287,455 to participating states. Wisconsin will receive $17,534 under the agreement.
Attorneys general from more than 40 states and the District of Columbia joined the settlement, including officials from New York, Texas, Florida, Pennsylvania, Illinois, Michigan, and several other jurisdictions.
AMCA Breach Led to Earlier Multistate Action
The Labcorp settlement follows earlier enforcement activity connected to the AMCA breach.
State attorneys general reached a separate settlement with AMCA in 2021 after the company’s bankruptcy petition was dismissed. The latest agreement instead examines the obligations of a healthcare company that entrusted patient information to an outside collection provider.
For organizations using collection agencies and other third-party vendors, the settlement reinforces the importance of treating cybersecurity oversight as an ongoing responsibility rather than a task that ends once a vendor contract is signed.
The requirements around contract controls, security assessments, data minimization, and vendor auditing also show how regulators are increasingly looking beyond the company where a breach occurs and examining the broader chain of organizations responsible for sensitive consumer data.