Skip to content
TrustList
News

Attorneys general settle with Labcorp over its debt collector’s breach and set out the vendor controls it must keep

Editorial

By TrustList Editorial

Forty-five US attorneys general settled with Labcorp on 24 September 2026 over the 2019 breach at its debt collector AMCA. Beyond $2,287,455, the terms require vendor-risk controls that any company outsourcing patient data can use as a checklist.

About Attorneys general settle with Labcorp over its debt collector’s breach and set out the vendor controls it must keep

Attorneys general settle with Labcorp over its debt collector's breach and set out the vendor controls it must keep

24 September 2026 — A group of 45 US state attorneys general announced a settlement with Labcorp on 24 September 2026 over the data breach at its former debt collector, American Medical Collection Agency (AMCA), between August 2018 and March 2019. The breach potentially exposed information on more than 27.5 million people, 10.2 million of them Labcorp patients. The multistate group was led by Connecticut, Florida, Illinois, Indiana, Michigan and Texas; the North Carolina, New York and Connecticut offices each published the terms.

The terms

Labcorp pays $2,287,455 to the states. The larger part of the settlement is what it must do:

  • keep an information security programme with an incident response plan that includes internal reporting of security events at vendors;
  • limit the patient data it shares with vendors to what they need;
  • run an expanded vendor risk-management programme with a dedicated team and tools for evaluating vendors;
  • for debt collectors specifically: keep an inventory of contracts, impose cybersecurity standards by contract, keep each client's data segregated, assess and audit the collectors, and be able to terminate for non-compliance;
  • have a third-party assessor review its information security, with a focus on vendor risk.

Connecticut's attorney general called data security a "non-delegable duty" for organisations covered by HIPAA: outsourcing a task does not outsource the responsibility.

Why it matters beyond Labcorp

The terms are effectively a regulator-approved checklist for managing vendors that hold sensitive data, and state attorneys general will measure other companies against similar standards after a vendor breach.

Who is affected

Healthcare providers, laboratories and insurers, and any company that sends personal data to collections agencies, billing services, claims processors, call centres or other outsourced vendors.

What to do

  • List the vendors that receive personal or health data, starting with collections and billing.
  • Check each contract for security standards, audit rights, breach notification to you, data segregation and termination for non-compliance.
  • Send vendors only the fields they need.
  • Make sure your incident response plan covers a breach that starts at a vendor, not only inside your own systems.
  • If you buy vendor risk-management software, check that it can hold contract terms, assessments and audit evidence per vendor.

Sources

Categories & features