Labcorp to Pay $2.3 Million and Overhaul Security After 2019 Data Breach

Summary
Labcorp settled a lawsuit brought by 44 state attorneys general, agreeing to pay $2.3 million and strengthen vendor security practices after a 2019 breach at debt collector AMCA exposed data belonging to 10.2 million Labcorp customers.
Key points
- The settlement resolves a lawsuit brought by a bipartisan coalition of 44 state attorneys general.
- The 2019 breach originated at Labcorp vendor American Medical Collection Agency (AMCA) and affected 10.2 million Labcorp customers; 27.5 million people nationwide were affected.
- Labcorp must strengthen vendor oversight, including cybersecurity requirements in contracts, routine compliance audits, and expanded risk management.
- The company must create an incident response plan for vendor security failures and limit the data it shares with vendors.
- Labcorp must retain an independent expert to conduct information security assessments and separate sensitive data shared with debt collectors.
Article Details
- Event Type
- Multistate settlement over a third-party data breach
- Impact
- A 2019 breach at Labcorp vendor American Medical Collection Agency exposed personal information belonging to about 10.2 million Labcorp customers and affected 27.5 million people nationwide. Labcorp agreed to a $2.3 million fine and reforms to vendor oversight, security controls and incident response.