Attorneys general settle with Labcorp over its debt collector’s breach and set out the vendor controls it must keep
EditorialBy TrustList Editorial
Forty-five US attorneys general settled with Labcorp on 24 September 2026 over the 2019 breach at its debt collector AMCA. Beyond $2,287,455, the terms require vendor-risk controls that any company outsourcing patient data can use as a checklist.
- United States of America
- North Carolina
- Burlington, North Carolina
- Connecticut
- +4 more
About Attorneys general settle with Labcorp over its debt collector’s breach and set out the vendor controls it must keep
Attorneys general settle with Labcorp over its debt collector's breach and set out the vendor controls it must keep
24 September 2026 — A group of 45 US state attorneys general announced a settlement with Labcorp on 24 September 2026 over the data breach at its former debt collector, American Medical Collection Agency (AMCA), between August 2018 and March 2019. The breach potentially exposed information on more than 27.5 million people, 10.2 million of them Labcorp patients. The multistate group was led by Connecticut, Florida, Illinois, Indiana, Michigan and Texas; the North Carolina, New York and Connecticut offices each published the terms.
The terms
Labcorp pays $2,287,455 to the states. The larger part of the settlement is what it must do:
- keep an information security programme with an incident response plan that includes internal reporting of security events at vendors;
- limit the patient data it shares with vendors to what they need;
- run an expanded vendor risk-management programme with a dedicated team and tools for evaluating vendors;
- for debt collectors specifically: keep an inventory of contracts, impose cybersecurity standards by contract, keep each client's data segregated, assess and audit the collectors, and be able to terminate for non-compliance;
- have a third-party assessor review its information security, with a focus on vendor risk.
Connecticut's attorney general called data security a "non-delegable duty" for organisations covered by HIPAA: outsourcing a task does not outsource the responsibility.
Why it matters beyond Labcorp
The terms are effectively a regulator-approved checklist for managing vendors that hold sensitive data, and state attorneys general will measure other companies against similar standards after a vendor breach.
Who is affected
Healthcare providers, laboratories and insurers, and any company that sends personal data to collections agencies, billing services, claims processors, call centres or other outsourced vendors.
What to do
- List the vendors that receive personal or health data, starting with collections and billing.
- Check each contract for security standards, audit rights, breach notification to you, data segregation and termination for non-compliance.
- Send vendors only the fields they need.
- Make sure your incident response plan covers a breach that starts at a vendor, not only inside your own systems.
- If you buy vendor risk-management software, check that it can hold contract terms, assessments and audit evidence per vendor.
Sources
- North Carolina Department of Justice: Attorney General Jeff Jackson reaches $2.2 million settlement with Labcorp over 2019 data breach — 24 September 2026
- New York Attorney General: Attorney General James secures $2.3 million and reforms to protect consumers after data breach — 24 September 2026
- Connecticut Attorney General: Attorney General Tong leads multistate settlement with Labcorp — 24 September 2026
Categories & features
- United States of America
- North Carolina
- Burlington, North Carolina
- Connecticut
- Vendor Management Software
- Vendor Management
- Risk Management
- Cybersecurity
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United States of AmericaThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.