

Labcorp will pay approximately $2.3 million and make significant changes to how it protects patient information shared with outside vendors following an investigation into a massive 2019 data breach involving a third-party medical debt collector.
New York Attorney General Letitia James announced September 24 that New York had joined a bipartisan coalition of 43 other attorneys general in reaching the agreement with Laboratory Corporation of America, better known as Labcorp. According to the New York Attorney General’s announcement, the underlying breach potentially exposed personal information belonging to more than 27.5 million people nationwide.
Approximately 10.2 million of those affected were Labcorp patients, including about 420,000 New Yorkers.
Importantly, the hacker did not directly breach Labcorp’s own computer systems in this incident. Instead, the intrusion occurred at American Medical Collection Agency, or AMCA, a third-party debt collector that Labcorp used to collect certain unpaid patient balances.
Hacker Had Access for Months
AMCA, based in Elmsford, New York, specialized in collecting small-balance medical debts for laboratories and medical testing facilities.
According to the Attorney General’s investigation, a hacker gained access to AMCA’s internal system beginning August 1, 2018, and remained able to collect customer information until March 30, 2019.
The investigation also found that AMCA failed to detect the intrusion despite receiving multiple warnings from banks that processed its payments about a potential breach.
The New York Attorney General says information potentially exposed in the breach included Social Security numbers, payment-card information, names of medical tests and diagnostic codes.
Labcorp previously disclosed that its own systems were not affected by the AMCA incident and that it stopped sending new collection requests to AMCA after learning about the breach. The company also previously said it offered 24 months of free credit monitoring and identity-protection services to individuals whose Social Security numbers were affected.
Labcorp Must Pay More Than $2.28 Million
Under the new multistate agreement, Labcorp will pay a total of $2,287,455 to the participating states.
New York will receive $89,178 of that amount.
But the settlement goes considerably further than a financial payment. The states are requiring Labcorp to make changes intended to reduce the risk that sensitive patient information entrusted to outside companies will be exposed in another breach.
Those requirements are particularly relevant because a company’s cybersecurity risk doesn’t end when information leaves its own computer network.
Labcorp Must Change How It Handles Third-Party Vendors
Under the settlement, Labcorp must improve its information-security program and create an incident-response plan that addresses security breaches involving vendors.
The company must also minimize the amount of information it shares with vendors while balancing the information debt-collection companies need to satisfy their legal obligations.
Labcorp’s vendor-risk-management program must be expanded to include a dedicated team, vendor-assessment tools and procedures for verifying vendors’ compliance with security requirements.
Debt-collection companies handling Labcorp information will face additional requirements, including contractual cybersecurity standards, assessments and audits. Labcorp must also address how patient data is segmented when a collection company handles information belonging to multiple clients and include provisions allowing contracts to be terminated for noncompliance.
The agreement additionally requires Labcorp to hire an independent third party to conduct an information-security assessment focused specifically on vendor risk management.
The AMCA Breach Previously Led to a Separate Settlement
This isn’t the first multistate action arising from the AMCA breach.
In 2021, New York and other states reached a separate agreement with AMCA itself. That settlement included a $21 million payment that was suspended because AMCA had filed for bankruptcy.
The latest agreement focuses instead on Labcorp’s responsibility for protecting patient information when that information is shared with outside vendors.
For consumers, that distinction matters. A company doesn’t necessarily need to suffer an intrusion on its own network for customer information it collected to become exposed; vendors, payment processors, debt collectors and other third parties can also become points of vulnerability.
What Former Labcorp Patients Should Know
The settlement announcement doesn’t say that all 10.2 million Labcorp patients affected by the 2019 incident suffered identity theft or financial losses. It also doesn’t announce a new consumer compensation fund or instruct former patients to submit claims for a portion of the $2.3 million settlement.
Consumers therefore should be cautious about messages claiming they must provide banking information, pay a fee or click a link to collect money from this particular settlement.
Anyone concerned about information exposed in an old breach can still take basic identity-protection steps, including reviewing credit reports for unfamiliar accounts, monitoring financial statements and considering a credit freeze if Social Security information may have been compromised.
Consumers can obtain information about placing and removing a credit freeze through the Federal Trade Commission’s IdentityTheft.gov resources, and anyone who discovers evidence of identity theft can use the site to create a recovery plan.
The Labcorp settlement provides another reminder that sensitive information can remain vulnerable even after a company hands it to an outside contractor. For consumers, the 2019 breach may be old news, but for Labcorp, the resulting security obligations are continuing years later.
What to Read Next
Amway and Affiliates Agree to $225 Million Settlement Over Earnings and Recruiting Claims
TikTok and ByteDance Agree to $400 Million Settlement Over Children’s Privacy Allegations
The post Labcorp to Pay $2.3 Million After Data Breach Exposed Information of 10.2 Million Patients appeared first on Clever Dude Personal Finance & Money.