Labcorp to Pay $2.3 Million and Overhaul Security After 2019 Data Breach

· Original article ↗

Summary

Labcorp settled a lawsuit brought by 44 state attorneys general, agreeing to pay $2.3 million and strengthen vendor security practices after a 2019 breach at debt collector AMCA exposed data belonging to 10.2 million Labcorp customers.

Key points

  • The settlement resolves a lawsuit brought by a bipartisan coalition of 44 state attorneys general.
  • The 2019 breach originated at Labcorp vendor American Medical Collection Agency (AMCA) and affected 10.2 million Labcorp customers; 27.5 million people nationwide were affected.
  • Labcorp must strengthen vendor oversight, including cybersecurity requirements in contracts, routine compliance audits, and expanded risk management.
  • The company must create an incident response plan for vendor security failures and limit the data it shares with vendors.
  • Labcorp must retain an independent expert to conduct information security assessments and separate sensitive data shared with debt collectors.

Article Details

Event Type
Multistate settlement over a third-party data breach
Impact
A 2019 breach at Labcorp vendor American Medical Collection Agency exposed personal information belonging to about 10.2 million Labcorp customers and affected 27.5 million people nationwide. Labcorp agreed to a $2.3 million fine and reforms to vendor oversight, security controls and incident response.

Vendors

Countries

Industries