Labcorp: Attorney General Mike Hilgers Announces Multistate Settlement with Labcorp over the American Medical Collection Agency Data Breach

Labcorp: Attorney General Mike Hilgers Announces Multistate Settlement with Labcorp over the American Medical Collection Agency Data Breach

Labcorp Settles Multistate Data Breach Investigation Over 2019 AMCA Incident

Nebraska Attorney General Mike Hilgers announced a settlement between Labcorp and a coalition of 44 state attorneys general, resolving a multistate investigation into a 2019 data breach at Retrieval-Masters Creditors Bureau (AMCA), Labcorp’s debt collection vendor. The breach exposed the personal and sensitive information of over 27.5 million individuals nationwide, including 10.2 million Labcorp patients, with 9,777 Nebraska residents affected.

The breach occurred at AMCA, but the compromised data belonged to Labcorp’s patients, highlighting the risks of third-party vendor management in cybersecurity. While companies can outsource operations, they remain responsible for safeguarding customer data a principle reinforced by the settlement.

Under the agreement, Labcorp must implement enhanced vendor security measures, including:

  • Developing an incident response plan with internal reporting for vendor-related security events.
  • Minimizing data sharing with vendors while ensuring compliance with legal obligations.
  • Expanding its vendor risk management program, including dedicated teams, vendor evaluation tools, and compliance verification.
  • Applying specialized requirements for debt collectors, such as contract inventories, enforced cybersecurity standards, data segmentation, and audit rights.
  • Hiring a third-party assessor to evaluate its information security program, with a focus on vendor risk management.

The settlement includes a $2.29 million payment to the participating states, with Nebraska receiving $16,661. The investigation was led by attorneys general from Connecticut, Florida, Indiana, Illinois, Michigan, and Texas, with support from an executive committee and additional states.

The case underscores the growing scrutiny of vendor security practices and the legal accountability companies face for third-party breaches.

Source: https://chadronradio.com/attorney-general-mike-hilgers-announces-multistate-settlement-with-labcorp-over-the-american-medical-collection-agency-data-breach/

Labcorp cybersecurity rating report: https://www.rankiteo.com/company/labcorp

"id": "LAB1790281763",
"linkid": "labcorp",
"type": "Breach",
"date": "5/2019",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '10.2 million patients',
                        'industry': 'Medical Laboratory Services',
                        'location': 'United States',
                        'name': 'Labcorp',
                        'type': 'Healthcare'},
                       {'customers_affected': '27.5 million individuals '
                                              'nationwide',
                        'industry': 'Debt Collection',
                        'location': 'United States',
                        'name': 'Retrieval-Masters Creditors Bureau (AMCA)',
                        'type': 'Vendor'}],
 'attack_vector': 'Third-party vendor compromise',
 'data_breach': {'number_of_records_exposed': '27.5 million individuals',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High (personally identifiable '
                                        'information)',
                 'type_of_data_compromised': 'Personal and sensitive '
                                             'information'},
 'date_publicly_disclosed': '2019',
 'description': 'Labcorp settled a multistate investigation into a 2019 data '
                'breach at Retrieval-Masters Creditors Bureau (AMCA), its debt '
                'collection vendor. The breach exposed personal and sensitive '
                'information of over 27.5 million individuals, including 10.2 '
                'million Labcorp patients, highlighting third-party vendor '
                'risks in cybersecurity.',
 'impact': {'brand_reputation_impact': 'Yes',
            'data_compromised': 'Personal and sensitive information',
            'financial_loss': '$2.29 million (settlement payment)',
            'identity_theft_risk': 'Yes',
            'legal_liabilities': 'Multistate investigation settlement'},
 'investigation_status': 'Resolved (settlement reached)',
 'lessons_learned': 'Risks of third-party vendor management in cybersecurity; '
                    'companies remain responsible for safeguarding customer '
                    'data even when outsourcing operations.',
 'post_incident_analysis': {'corrective_actions': 'Enhanced vendor security '
                                                  'measures, incident response '
                                                  'plan development, vendor '
                                                  'risk management program '
                                                  'expansion, data sharing '
                                                  'minimization, and '
                                                  'third-party assessor '
                                                  'hiring.',
                            'root_causes': 'Third-party vendor compromise '
                                           '(AMCA)'},
 'recommendations': 'Implement enhanced vendor security measures, minimize '
                    'data sharing with vendors, expand vendor risk management '
                    'programs, apply specialized requirements for debt '
                    'collectors, and hire third-party assessors for security '
                    'evaluations.',
 'references': [{'source': 'Nebraska Attorney General Mike Hilgers'}],
 'regulatory_compliance': {'fines_imposed': '$2.29 million settlement',
                           'legal_actions': 'Multistate investigation led by '
                                            'Connecticut, Florida, Indiana, '
                                            'Illinois, Michigan, and Texas'},
 'response': {'incident_response_plan_activated': 'Yes (enhanced vendor '
                                                  'security measures)',
              'network_segmentation': 'Data segmentation for debt collectors',
              'remediation_measures': 'Enhanced vendor security measures, data '
                                      'sharing minimization, vendor risk '
                                      'management program expansion',
              'third_party_assistance': 'Third-party assessor hired to '
                                        'evaluate information security '
                                        'program'},
 'title': 'Labcorp Settles Multistate Data Breach Investigation Over 2019 AMCA '
          'Incident',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.