LabCorp Agrees to $2.2M Settlement Over 2019 Third-Party Data Breach
LabCorp will pay $2.2 million to 42 states and Washington D.C. to settle litigation over a 2019 data breach affecting 10.2 million patients, stemming from a third-party vendor compromise.

LabCorp has agreed to a $2.2 million settlement with 42 states and the District of Columbia to resolve litigation arising from a significant data breach in 2019. The breach, which impacted approximately 10.2 million patients, originated from a compromise at a third-party vendor that handled LabCorp's data, underscoring the pervasive risks associated with supply chain vulnerabilities in the healthcare sector.
The settlement mandates that LabCorp implement enhanced data security measures and strengthen its vendor risk management practices. This includes more rigorous oversight of third-party service providers that have access to sensitive patient information. The agreement aims to prevent future incidents and ensure greater protection for the personal health information of millions of individuals.
The incident first came to light when American Medical Collection Agency (AMCA), a third-party billing and collections firm, disclosed that its systems had been breached. The attackers gained access to AMCA's network between August 1, 2018, and March 30, 2019, exfiltrating data that included names, addresses, dates of birth, Social Security numbers, and medical information of patients whose accounts were serviced by AMCA.
LabCorp, along with other healthcare providers that used AMCA's services, faced scrutiny over their data security protocols and vendor vetting processes. The multistate investigation focused on whether these companies adequately protected patient data entrusted to their third-party partners. The settlement with LabCorp is part of a broader effort by state attorneys general to hold companies accountable for data protection failures.
While the settlement resolves the multistate litigation, it does not preclude individual patients from pursuing separate legal action. The agreement requires LabCorp to notify affected individuals and provide credit monitoring services, though the specifics of these provisions are detailed within the settlement terms.
This case highlights a recurring theme in cybersecurity: the critical importance of robust third-party risk management. As organizations increasingly rely on external vendors for specialized services, the security posture of these vendors becomes a direct extension of their own. The settlement serves as a stark reminder that comprehensive security strategies must encompass the entire ecosystem of partners and suppliers.
LabCorp's commitment to improving its security and vendor oversight practices is a necessary step in rebuilding trust and ensuring compliance with evolving data privacy regulations. The $2.2 million payment, while substantial, is secondary to the long-term imperative of safeguarding patient data against increasingly sophisticated cyber threats.
The settlement details expand on the initial reporting by specifying that Labcorp will pay $2.3 million to 44 state attorneys general, an increase from the $2.2 million previously reported. Furthermore, the company is mandated to create a specific incident response plan for vendor security failures, limit data sharing with third parties, and establish a dedicated risk management team to oversee vendor compliance with new cybersecurity protocols.