Labcorp will pay nearly $2.3 million and overhaul how it protects patient information shared with outside vendors following a multistate investigation into a massive 2019 data breach.
The breach occurred at American Medical Collection Agency, or AMCA, a third-party medical debt collector used by Labcorp and other health care companies. It potentially exposed personal information belonging to more than 27.5 million people nationwide, including approximately 10.2 million Labcorp patients.
The settlement announced in September by New York Attorney General Letitia James and a bipartisan coalition of 43 other attorneys general requires Labcorp to pay $2,287,455 to participating states. New York will receive $89,178 under the agreement.
The Breach Happened at a Labcorp Debt Collector
AMCA, formally known as Retrieval-Masters Creditors Bureau, specialized in collecting small medical debts for laboratories and testing facilities.
Between Aug. 1, 2018, and March 30, 2019, an unauthorized user gained access to AMCA’s internal systems. According to the New York Attorney General’s Office, AMCA failed to detect the intrusion despite receiving multiple warnings from banks processing payments about a potential security breach.
The broader AMCA breach potentially exposed highly sensitive information, including Social Security numbers, payment-card information and certain medical information.
Labcorp has provided additional detail about its patients’ information. In an August 2026 filing with the Securities and Exchange Commission, the company said information from Labcorp on AMCA’s affected system may have included names, addresses, balances, phone numbers, dates of birth, referring physicians, dates of service and, for some people, health insurance information and Social Security numbers.
Labcorp said its own computer systems weren’t affected by the AMCA incident and that ordered tests, laboratory test results and diagnostic information from the company weren’t on AMCA’s affected system.
Labcorp Must Strengthen Oversight of Outside Vendors
The settlement goes beyond the nearly $2.3 million payment.
Labcorp must improve its information-security program and create an incident-response plan that includes internal reporting of security events involving vendors. The company must also minimize the amount of information shared with vendors while accounting for debt collectors’ legal obligations.
The agreement requires Labcorp to expand its vendor-risk management program, including establishing a dedicated team, using tools to evaluate vendors and verifying that vendors comply with security requirements.
Debt collectors will receive additional scrutiny. Requirements include enforcing cybersecurity standards through contracts, maintaining inventories of contracts, segmenting certain data, conducting assessments and audits and allowing Labcorp to terminate relationships for noncompliance.
Labcorp must also hire a third-party assessor to conduct an information-security assessment focused on vendor risk management.
The Settlement Follows Earlier Action Against AMCA
The Labcorp agreement isn’t the first settlement stemming from the breach.
The multistate coalition reached a separate settlement with AMCA in 2021 that included a $21 million payment that was suspended because of the company’s financial condition and bankruptcy.
The Pennsylvania Attorney General’s Office also notes that Labcorp separately agreed to a $35 million settlement in related federal class-action litigation, although that litigation involves other AMCA clients as well and is separate from the states’ $2.3 million settlement.
The new multistate agreement therefore addresses Labcorp’s responsibilities for safeguarding patient information entrusted to outside companies rather than imposing a penalty on AMCA itself.
What Consumers Should Take Away From the Settlement
The incident offers a reminder that sensitive personal information can leave a company’s own computer network when businesses use outside vendors for services such as debt collection.
For anyone previously notified that their Social Security number or financial information was involved in a breach, the Federal Trade Commission’s IdentityTheft.gov provides steps for responding to identity theft and creating a personalized recovery plan. Consumers can also obtain free credit reports through AnnualCreditReport.com and consider a credit freeze when they believe sensitive identifying information may have been compromised.
Because this breach occurred years ago, consumers shouldn’t assume the new $2.3 million multistate settlement automatically means they’re entitled to a payment. The attorneys general’s settlement primarily requires payments to participating states and changes to Labcorp’s data-security practices.
Anyone who received an original breach notification or believes their information was affected should rely on official Labcorp, court or state attorney general information when determining whether any separate consumer remedy applies.
What to Read Next
SSA Is Releasing New Social Security Data in Stages—Here’s What Retirees Should Watch
The Everyday Phone Habit Cybersecurity Experts Say Could Put Your Personal Data at Risk