Labcorp has agreed to a $2.29 million settlement following a multistate investigation into a 2019 data breach. The breach involved its previous debt collection vendor, the American Medical Collection Agency (AMCA).
What happened
The Colorado Attorney General’s Office announced on September 24, 2026, that Labcorp has agreed to a $2.29 million multistate settlement over a 2019 data breach involving its former debt collection vendor, the American Medical Collection Agency (AMCA). The announcement came from Colorado Attorney General Phil Weiser’s office, which said the settlement resolves a multistate investigation into Labcorp’s handling and oversight of patient information shared with AMCA.
The AMCA breach potentially exposed the personal information of more than 27.5 million people in the US, including approximately 10.2 million Labcorp patients. The settlement involves a coalition of attorneys general from 44 states and the District of Columbia, with Labcorp agreeing to pay $2,287,455 to the participating states. Colorado is expected to receive approximately $32,086.
The settlement also requires Labcorp to strengthen its vendor risk management practices, including limiting the information shared with vendors, assessing vendors’ security practices, and imposing additional cybersecurity requirements on debt collection companies that handle patient information.
The backstory
The incident originated in 2019, when hackers infiltrated AMCA's computer systems. According to Labcorp, an unauthorized user had access to AMCA’s systems between August 1, 2018, and March 30, 2019.
Labcorp had sent certain patient accounts to AMCA for debt collection after its own efforts to collect outstanding balances were unsuccessful. Information held by AMCA potentially included patients’ names, addresses, telephone numbers, dates of birth, referring physicians, dates of service, and account balances. Some individuals may also have had health insurance information and Social Security numbers exposed. Labcorp said its own systems were not affected and that laboratory test results and diagnostic information were not stored on the affected AMCA systems.
The breach ultimately affected information belonging to millions of people. Claim Depot reports that patients whose information Labcorp transmitted to AMCA between August 2018 and March 2019 were included in a $35 million class-action settlement. The settlement was granted final approval on August 20, 2026.
The class-action settlement is separate from the $2.29 million multistate settlement announced in September 2026. While the class action provides a mechanism for affected individuals to receive compensation, the multistate agreement focuses on changes to Labcorp’s security and vendor-management practices following the breach.
Labcorp has denied wrongdoing or liability in the class-action case, according to Claim Depot, and the parties agreed to settle to avoid the costs and risks associated with continued litigation.
Going deeper
The settlement focuses heavily on third-party and vendor risk management rather than simply requiring Labcorp to improve its own internal security. Under the agreement, Labcorp must strengthen aspects of its information security program, including an incident response plan that requires security incidents involving vendors to be reported internally.
The company must also reduce the amount of patient information shared with vendors, where possible, and establish a dedicated vendor risk management function. That program must include tools for assessing vendors and processes for verifying that vendors comply with security requirements.
The agreement contains additional requirements for debt collection vendors. Labcorp must maintain inventories of relevant contracts, impose cybersecurity requirements through those contracts, and ensure that data held by debt collectors for different healthcare organizations is appropriately segmented.
Debt collectors will also be subject to security assessments and audits, with contracts required to include termination rights when vendors fail to meet security requirements. Labcorp must additionally hire an independent third-party assessor to evaluate its information security program, with a particular focus on vendor risk management.
Why it matters
The case reinforces that vendor management is not simply a procurement issue. When third parties handle patient information, their security practices can become part of the healthcare organization's broader privacy and compliance risk.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQS
What is a third-party vendor risk?
Third-party vendor risk refers to the security and privacy risks that arise when an organization gives another company access to its systems or sensitive information. In healthcare, these vendors may handle protected health information (PHI), financial information, or other sensitive patient data.
How does HIPAA require healthcare organizations to oversee vendors?
HIPAA requires covered entities to have written agreements with business associates that establish permitted uses and disclosures of protected health information and require appropriate safeguards.
Can a covered entity be held responsible for a vendor's data breach?
Yes. Under HIPAA, a covered entity may be held responsible for certain failures involving its business associates, particularly if it fails to obtain appropriate assurances, establish a required business associate agreement, or take reasonable steps to address known noncompliance. Business associates also have their own direct HIPAA obligations.
