The news
The Labcorp settlement announced on September 24 by New York Attorney General Letitia James requires clinical laboratory company Labcorp (LH) to pay $2,287,455 to a coalition of 44 attorneys general and overhaul how it protects patient data shared with vendors.
The case stems from a breach at American Medical Collection Agency (AMCA), a debt collector that worked for Labcorp. According to the New York attorney general's office, a hacker had access to AMCA's systems from August 1, 2018, to March 30, 2019. The intrusion exposed personal information on more than 27.5 million people nationwide, including 10.2 million Labcorp patients, about 420,000 of whom lived in New York. The office said AMCA failed to detect the intrusion despite warnings from banks.
Exposed data included Social Security numbers, payment card information and medical test and diagnostic codes, the office said. New York's share of the payment is $89,178. The Record reported that Labcorp did not immediately respond to a request for comment.
Most of the settlement focuses on vendor oversight. Labcorp must strengthen its information security program and incident response plans, limit the data it shares with vendors to what debt collection requires, and build a risk management function to check vendor compliance. It must set cybersecurity standards for debt collectors, with the right to end contracts for noncompliance, segment data held by collectors, and hire a third-party assessor to evaluate its security.
HIPAA Journal reported further terms, including that Labcorp employ a chief information security officer, provide security awareness training to staff who handle personal and health information, and require debt collectors to conduct penetration testing and obtain annual SOC 2 Type 2 audits, an independent review of a service provider's security controls. The outlet also reported that Labcorp agreed to a separate $35 million class action settlement earlier in 2026.
The numbers
- Total settlement payment
- $2,287,455
- New York's share
- $89,178
- Attorneys general in the coalition
- 44
- People affected by the AMCA breach nationwide
- More than 27.5 million
- Labcorp patients affected
- 10.2 million
- Labcorp patients in New York affected
- About 420,000
Why CEOs should care
For general counsels and boards, the key point is liability. The breach happened at a vendor, yet state enforcers pursued the company that shared the data. Attorney General James framed the case simply: “Corporations have a responsibility to protect their customers' private data, especially sensitive medical information.” Boards should ask management which vendors hold regulated data, how that data is minimized before it leaves the company, and who owns vendor security oversight.
For CISOs and procurement leaders, the settlement terms read like a checklist regulators may expect elsewhere. They include contractual security standards with termination rights, penetration testing and annual SOC 2 Type 2 audits for debt collectors, a dedicated vendor risk team, and segmentation so one collector cannot aggregate data across clients. Companies that send patient or customer data to collection agencies, billing firms or claims processors should compare current contracts with these terms. Procurement teams should also confirm that vendor contracts require prompt breach notification, since AMCA's intrusion ran for roughly eight months before it ended.
For CFOs, the $2.3 million payment is modest next to the $35 million class action HIPAA Journal reported, and both sit on top of years of remediation and legal cost. The case shows how long a vendor breach can stay on the books: the intrusion ended in March 2019, and enforcement closed in September 2026.
The bigger picture
State attorneys general have brought a series of data breach cases, often acting in large bipartisan coalitions; the New York attorney general's office pointed to earlier settlements with 23andMe, Illuminate Education and eight car insurance companies. This settlement pairs a payment with specific required controls, such as an outside assessment and vendor audits, rather than relying on a fine alone. The AMCA breach also reached well beyond Labcorp: of the more than 27.5 million people exposed nationwide, 10.2 million were Labcorp patients, according to New York's attorney general. A single collection agency serving many clients became a concentration point for sensitive data from across the healthcare sector.
The case also reflects a wider shift in third-party risk management, where companies are expected to prove, not assume, that suppliers holding their data meet defined security standards.
What’s next
Watch for how Labcorp reports on compliance with the settlement's assessment and vendor-audit requirements, and whether other companies tied to the AMCA breach face similar state action. The coalition has already settled with AMCA itself: a 2021 multistate agreement included a $21 million payment that was suspended because of the company's bankruptcy, according to the New York attorney general's office. Organizations should review data-sharing agreements with debt collectors and billing vendors before their own contracts come up for renewal.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





