← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Labcorp fined $2.3M and mandated to overhaul data security after 2019 breach

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Labcorp fined $2.3 million by 44 state attorneys general.
  • Settlement follows a 2019 data breach impacting 10.2 million customers.
  • Breach originated from security failings at debt collector AMCA.
  • Labcorp must implement new vendor security and data protection measures.

Settlement Reached for 2019 Data Breach

A bipartisan coalition of 44 state attorneys general announced a settlement with Labcorp. The agreement requires Labcorp to pay a $2.3 million fine and implement significant data security reforms. This action stems from a 2019 data breach that exposed the information of 10.2 million Labcorp customers.

Origin of the Breach

The data breach originated with American Medical Collection Agency (AMCA), a debt collector that worked with Labcorp. The attorneys general argued that Labcorp failed to adequately oversee AMCA's security practices, despite the incident impacting a total of 27.5 million individuals nationwide through AMCA.

In 2021, a court ordered AMCA to pay a $21 million fine, which was suspended due to the company's bankruptcy.

Mandated Security Reforms

Under the settlement, Labcorp must implement several security changes. These include creating an incident response plan specifically for vendor security failings, limiting the amount of data shared with vendors, and establishing a risk management team to monitor vendor compliance with data security practices.

Additionally, Labcorp is required to include cybersecurity requirements in vendor contracts and mandate that data collectors provide routine audits documenting their compliance. The company must also retain an independent expert for information security assessments and begin siloing data that debt collectors often aggregate from multiple clients.

Impact on Patient Data Protection

New York Attorney General Letitia James stated that the settlement aims to prevent future data breaches and protect patient information. The reforms are intended to address Labcorp's past failures in safeguarding customer data, particularly concerning third-party vendor relationships.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~17 min · 13 stories · Sep 25

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Labcorp will pay a $2.3 million fine and implement extensive data security reforms following a 2019 data breach that affected 10.2 million customers. A coalition of 44 state attorneys general settled a lawsuit, requiring Labcorp to improve vendor oversight and data protection practices.