Light bulb Limited Spots Available: Secure Your Lifetime Subscription on Gumroad!

Sep 27, 2026 · 6 min read

Labcorp Settlement: 44 AGs Get $2.3M Over Vendor Breach

On September 24, 2026, a coalition of 44 state attorneys general settled with Labcorp over the 2019 American Medical Collection Agency breach. The debt collector was the one hacked. Labcorp is the one now rewriting how it shares patient data with vendors.

Labcorp never lost control of its own servers. The company that did was American Medical Collection Agency (AMCA), a debt collector Labcorp handed unpaid patient bills to. A hacker sat inside AMCA's systems for eight months, and more than seven years later, the states have decided that the lab that chose the vendor also owns the failure.

Key Takeaways

  • Labcorp agreed to pay $2,287,455 to 44 state attorneys general on September 24, 2026, according to the New York Attorney General's announcement.
  • AMCA, Labcorp's debt collection vendor, was breached between August 1, 2018 and March 30, 2019, exposing data on 27.5 million people, including 10.2 million Labcorp patients.
  • The settlement forces Labcorp to minimize the data it shares with vendors, contractually require security standards from debt collectors, audit them, and hire an independent assessor focused on vendor risk.
  • The penalty works out to about 22 cents per affected Labcorp patient, so the real weight of the deal sits in the vendor oversight terms, not the dollar figure.

What Is the Labcorp Settlement?

The Labcorp settlement is a $2.3 million multistate agreement that resolves an investigation into how Labcorp handled patient data it passed to AMCA. The money is split among the 44 participating attorneys general, which by Connecticut's tally means 43 states plus the District of Columbia. New York receives $89,178 for roughly 420,000 affected residents, and Connecticut receives $81,296 for 43,666 residents, according to the Connecticut Attorney General's press release.

Connecticut, Florida, Illinois, Indiana, Michigan and Texas led the investigation. Maryland, Massachusetts, New York, North Carolina and Tennessee sat on the executive committee, and 32 more states plus the District of Columbia joined.

"Millions of patients' private health information was potentially exposed because of Labcorp's failures to protect its customers," said New York Attorney General Letitia James. Connecticut Attorney General William Tong put the theory of liability more bluntly: "Labcorp outsourced their debt collection, and they shared sensitive personal information for millions of patients that was ultimately compromised."

Labcorp did not respond to requests for comment and issued no press release, The Record reported.

What Happened in the AMCA Data Breach?

Attackers compromised AMCA's web payments page and kept access from August 1, 2018 until March 30, 2019. Researchers at Gemini Advisory found about 200,000 payment cards linked to AMCA for sale online, as Krebs on Security reported in June 2019. The New York AG says banks that processed AMCA's payments sent "numerous warnings" about a potential breach, and AMCA still failed to detect the intrusion.

Across AMCA's clients, the exposed data included:

  • Social Security numbers
  • Payment card information
  • Names of medical tests and diagnostic codes, in some cases
  • Names, dates of birth, addresses, phone numbers, dates of service, provider and balance details

Labcorp was not the only lab caught up. Quest Diagnostics reported about 11.9 million affected patients in 2019. AMCA's parent company, Retrieval-Masters Creditors Bureau, filed for Chapter 11 in June 2019 after spending $3.8 million to mail breach notices, SecurityWeek reported. In 2021, a separate multistate settlement ordered AMCA to pay $21 million, a penalty suspended because of its finances.

The Labcorp number also grew. In June 2019, Labcorp put its exposure at 7.7 million patients. The attorneys general now cite 10.2 million, an increase of about a third.

Rack of blood sample tubes behind a stack of sealed envelopes and a closed laptop on a lab counter, illustrating the AMCA debt collector breach behind the Labcorp settlement

What Must Labcorp Change?

Labcorp must rebuild how it selects, feeds and supervises vendors, with debt collectors singled out for extra controls. The terms, drawn from the New York and Connecticut announcements, read like a third party vendor risk checklist:

  • Vendor incident response. The incident response plan must cover security events at vendors, not only inside Labcorp.
  • Data minimization. Share only the data a vendor needs to perform the service.
  • A dedicated vendor risk team. Staff whose job is verifying vendor compliance.
  • Contractual security standards. Cybersecurity requirements written into debt collector contracts, with a right to terminate for noncompliance.
  • Assessments and audits. Debt collectors must perform risk assessments and audits of their own controls.
  • Data segmentation. Collectors that pool records from many clients must keep Labcorp's data separate.
  • Independent assessor. A third party assessor will review the program, with a focus on vendor risk management.

Is $2.3 Million a Meaningful Penalty?

Measured per patient, no. $2,287,455 spread across 10.2 million Labcorp patients is about 22 cents each. Labcorp's separate $35 million class action settlement, reported by BankInfoSecurity in June 2026, is roughly 15 times larger.

The precedent is what matters. Earlier this week we covered Sweden's fine against Miljödata, where the regulator went after the vendor. Here the vendor is bankrupt, so the states went after the client that chose it. Put the two cases together and neither side of an outsourcing relationship can count on the other absorbing the liability.

What This Means for Your Inbox

Your email service provider is a vendor too. Every company that exports its customer list to a newsletter platform, CRM or marketing agency is doing what Labcorp did with AMCA: handing personal data to a third party and trusting it to keep that data safe. The attorneys general have now spelled out what "trusting" should look like, and an email list full of names and purchase history fits the same logic as a list of patient balances.

For patients, the leaked fields are ideal phishing material. A message quoting your real provider, date of service and outstanding balance looks like a legitimate bill. Stolen credentials already drive healthcare's worst email breaches, and billing lures are an easy extension of that playbook. If you were a Labcorp or Quest patient in 2018 or 2019:

  • Verify any email or text about an old lab bill by calling the number on a statement you already have.
  • Never enter card details or your Social Security number through a link in an unexpected collection notice.
  • Consider a free credit freeze, which the FTC explains here, since exposed Social Security numbers do not expire.

What Should Compliance Teams Do Now?

Compliance teams should run the Labcorp terms against their own vendor inventory, starting with any vendor that aggregates data from many clients. Debt collectors, payroll providers and marketing platforms all fit that profile, and a single breached vendor exposed customers of 80 banks earlier this year. Practical questions to ask:

  • Does your incident response plan name who acts when a vendor, not you, is breached?
  • Can you list exactly which fields each vendor receives, and justify every one?
  • Do your contracts include security standards, audit rights and termination for noncompliance?
  • Is your data segmented from other clients' data in multitenant vendors?

For a structured baseline, NIST SP 800-161 Rev. 1 covers supply chain risk management practices that map closely to what the states demanded. The AMCA breach took seven years to reach this settlement. Your next vendor incident will not wait that long to reach your inbox.

Stop Email Tracking in Gmail

Spy pixels track when you open emails, where you are, and what device you use. Gblock blocks them automatically.

Try Gblock Free for 30 Days

No credit card required. Works with Chrome, Edge, Brave, and Arc.