Skip to content
TECH CEO Daily

Labcorp settlement with 44 attorneys general sets $2.3 million penalty over vendor breach

The deal targets how Labcorp oversees debt collectors and other vendors, seven years after a breach at collection agency AMCA exposed data on more than 27.5 million people.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Labcorp agreed to pay $2,287,455 to 44 attorneys general over the 2018-2019 breach at its debt collector AMCA.
  • 2The AMCA breach exposed data on more than 27.5 million people, including 10.2 million Labcorp patients, per New York's attorney general.
  • 3Terms require vendor risk management, limits on data shared with collectors, data segmentation and an outside security assessment.

The news

The Labcorp settlement announced on September 24 by New York Attorney General Letitia James requires clinical laboratory company Labcorp (LH) to pay $2,287,455 to a coalition of 44 attorneys general and overhaul how it protects patient data shared with vendors.

The case stems from a breach at American Medical Collection Agency (AMCA), a debt collector that worked for Labcorp. According to the New York attorney general's office, a hacker had access to AMCA's systems from August 1, 2018, to March 30, 2019. The intrusion exposed personal information on more than 27.5 million people nationwide, including 10.2 million Labcorp patients, about 420,000 of whom lived in New York. The office said AMCA failed to detect the intrusion despite warnings from banks.

Exposed data included Social Security numbers, payment card information and medical test and diagnostic codes, the office said. New York's share of the payment is $89,178. The Record reported that Labcorp did not immediately respond to a request for comment.

Most of the settlement focuses on vendor oversight. Labcorp must strengthen its information security program and incident response plans, limit the data it shares with vendors to what debt collection requires, and build a risk management function to check vendor compliance. It must set cybersecurity standards for debt collectors, with the right to end contracts for noncompliance, segment data held by collectors, and hire a third-party assessor to evaluate its security.

HIPAA Journal reported further terms, including that Labcorp employ a chief information security officer, provide security awareness training to staff who handle personal and health information, and require debt collectors to conduct penetration testing and obtain annual SOC 2 Type 2 audits, an independent review of a service provider's security controls. The outlet also reported that Labcorp agreed to a separate $35 million class action settlement earlier in 2026.

The numbers

Total settlement payment
$2,287,455
New York's share
$89,178
Attorneys general in the coalition
44
People affected by the AMCA breach nationwide
More than 27.5 million
Labcorp patients affected
10.2 million
Labcorp patients in New York affected
About 420,000

Why CEOs should care

For general counsels and boards, the key point is liability. The breach happened at a vendor, yet state enforcers pursued the company that shared the data. Attorney General James framed the case simply: “Corporations have a responsibility to protect their customers' private data, especially sensitive medical information.” Boards should ask management which vendors hold regulated data, how that data is minimized before it leaves the company, and who owns vendor security oversight.

For CISOs and procurement leaders, the settlement terms read like a checklist regulators may expect elsewhere. They include contractual security standards with termination rights, penetration testing and annual SOC 2 Type 2 audits for debt collectors, a dedicated vendor risk team, and segmentation so one collector cannot aggregate data across clients. Companies that send patient or customer data to collection agencies, billing firms or claims processors should compare current contracts with these terms. Procurement teams should also confirm that vendor contracts require prompt breach notification, since AMCA's intrusion ran for roughly eight months before it ended.

For CFOs, the $2.3 million payment is modest next to the $35 million class action HIPAA Journal reported, and both sit on top of years of remediation and legal cost. The case shows how long a vendor breach can stay on the books: the intrusion ended in March 2019, and enforcement closed in September 2026.

The bigger picture

State attorneys general have brought a series of data breach cases, often acting in large bipartisan coalitions; the New York attorney general's office pointed to earlier settlements with 23andMe, Illuminate Education and eight car insurance companies. This settlement pairs a payment with specific required controls, such as an outside assessment and vendor audits, rather than relying on a fine alone. The AMCA breach also reached well beyond Labcorp: of the more than 27.5 million people exposed nationwide, 10.2 million were Labcorp patients, according to New York's attorney general. A single collection agency serving many clients became a concentration point for sensitive data from across the healthcare sector.

The case also reflects a wider shift in third-party risk management, where companies are expected to prove, not assume, that suppliers holding their data meet defined security standards.

What’s next

Watch for how Labcorp reports on compliance with the settlement's assessment and vendor-audit requirements, and whether other companies tied to the AMCA breach face similar state action. The coalition has already settled with AMCA itself: a 2021 multistate agreement included a $21 million payment that was suspended because of the company's bankruptcy, according to the New York attorney general's office. Organizations should review data-sharing agreements with debt collectors and billing vendors before their own contracts come up for renewal.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

LabcorpAMCAState attorneys generalVendor risk

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.