Labcorp Settles $2.3M Over 2019 Data Breach Affecting 27.5 Million Patients
A bipartisan coalition of 44 state attorneys general, led by New York Attorney General Letitia James, has secured a $2.3 million settlement with Labcorp over a 2019 data breach that exposed the personal and medical information of over 27.5 million people including 10.2 million Labcorp patients. The breach stemmed from a cyberattack on American Medical Collection Agency (AMCA), a third-party debt collector for Labcorp, between August 2018 and March 2019.
Hackers infiltrated AMCA’s systems, compromising Social Security numbers, payment card details, and medical test information. Despite warnings from banks about suspicious activity, AMCA failed to detect the intrusion, resulting in one of the largest healthcare-related breaches in U.S. history. New York alone accounted for 420,000 affected individuals.
Under the settlement, Labcorp must implement sweeping cybersecurity reforms, including:
- Strengthening its information security program and incident response plan.
- Minimizing data shared with vendors while ensuring compliance with legal obligations.
- Expanding vendor risk management with dedicated oversight and compliance verification.
- Enforcing stricter cybersecurity standards in vendor contracts, including data segmentation and regular audits.
- Engaging a third-party assessor to evaluate its security practices, with a focus on vendor risk management.
Labcorp will pay $2,287,455 to the participating states, including $89,178 to New York. The settlement follows a 2021 multistate agreement with AMCA, which included a $21 million penalty later suspended due to the company’s bankruptcy.
The case reflects a broader enforcement trend by James’ office, which has secured multimillion-dollar settlements from companies like 23andMe, Illuminate Education, and auto insurers over similar data protection failures.
Labcorp cybersecurity rating report: https://www.rankiteo.com/company/labcorp
"id": "LAB1790325079",
"linkid": "labcorp",
"type": "Breach",
"date": "8/2018",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '10.2 million Labcorp patients',
'industry': 'Medical Testing and Diagnostics',
'location': 'United States',
'name': 'Labcorp',
'type': 'Healthcare'},
{'customers_affected': '27.5 million individuals '
'(including Labcorp patients)',
'industry': 'Financial Services',
'location': 'United States',
'name': 'American Medical Collection Agency (AMCA)',
'type': 'Third-party debt collector'}],
'attack_vector': 'Third-party vendor compromise',
'data_breach': {'number_of_records_exposed': '27.5 million',
'personally_identifiable_information': 'Yes (Social Security '
'numbers, payment card '
'details)',
'sensitivity_of_data': 'High (PII, medical data, financial '
'data)',
'type_of_data_compromised': ['Personal information',
'Medical information',
'Social Security numbers',
'Payment card details']},
'date_publicly_disclosed': '2019',
'description': 'A bipartisan coalition of 44 state attorneys general secured '
'a $2.3 million settlement with Labcorp over a 2019 data '
'breach that exposed the personal and medical information of '
'over 27.5 million people, including 10.2 million Labcorp '
'patients. The breach stemmed from a cyberattack on American '
'Medical Collection Agency (AMCA), a third-party debt '
'collector for Labcorp, between August 2018 and March 2019. '
'Hackers infiltrated AMCA’s systems, compromising Social '
'Security numbers, payment card details, and medical test '
'information.',
'impact': {'brand_reputation_impact': 'Significant (multistate settlement and '
'enforcement trend)',
'data_compromised': 'Personal and medical information, Social '
'Security numbers, payment card details, '
'medical test information',
'financial_loss': '$2,287,455 (settlement amount)',
'identity_theft_risk': 'High (Social Security numbers and payment '
'card details exposed)',
'legal_liabilities': 'Multistate settlement, regulatory '
'enforcement',
'payment_information_risk': 'High (payment card details exposed)',
'systems_affected': 'AMCA’s systems (third-party debt collector)'},
'investigation_status': 'Settled',
'lessons_learned': 'Third-party vendor risk management is critical; failure '
'to detect intrusions can lead to massive breaches; '
'regulatory enforcement is increasing for data protection '
'failures.',
'post_incident_analysis': {'corrective_actions': 'Implementation of sweeping '
'cybersecurity reforms, '
'including vendor risk '
'management and third-party '
'assessments',
'root_causes': 'Failure to detect intrusion by '
'AMCA despite warnings from banks; '
'inadequate vendor risk management '
'by Labcorp'},
'recommendations': ['Strengthen information security programs and incident '
'response plans',
'Minimize data shared with vendors and ensure compliance '
'with legal obligations',
'Expand vendor risk management with dedicated oversight '
'and compliance verification',
'Enforce stricter cybersecurity standards in vendor '
'contracts, including data segmentation and regular '
'audits',
'Engage third-party assessors to evaluate security '
'practices, particularly vendor risk management'],
'references': [{'source': 'New York Attorney General Press Release'}],
'regulatory_compliance': {'fines_imposed': '$2,287,455 (settlement amount)',
'legal_actions': 'Multistate settlement led by New '
'York Attorney General Letitia '
'James'},
'response': {'network_segmentation': 'Data segmentation (required in vendor '
'contracts)',
'remediation_measures': 'Strengthening information security '
'program and incident response plan, '
'minimizing data shared with vendors, '
'expanding vendor risk management, '
'enforcing stricter cybersecurity '
'standards in vendor contracts, engaging '
'a third-party assessor to evaluate '
'security practices'},
'title': 'Labcorp Settles $2.3M Over 2019 Data Breach Affecting 27.5 Million '
'Patients',
'type': 'Data Breach'}