AMCA fallout lands Labcorp with a $2.3M bill and new vendor rules

Labcorp will pay $2.3M and rebuild how it polices data vendors after a 2019 breach that exposed 10.2 million of its patients.

MedRisk Staff
By
2 Min Read

Labcorp has agreed to pay $2.3 million and rewrite how it oversees data vendors, closing a multistate investigation into a 2019 breach that touched more than 10 million of its patients.

The settlement, announced Thursday by a bipartisan coalition of 44 state attorneys general, resolves allegations tied to American Medical Collection Agency (AMCA), a debt collector the clinical laboratory giant used to pursue unpaid bills. Attackers sat inside AMCA’s network from August 2018 until March 2019, and the intrusion was not spotted until the collector’s parent company found it the following spring. Names, Social Security numbers, financial details, medical test information, and diagnostic codes spilled out. The final count across its customers came to 27.5 million records, and no larger breach hit a HIPAA-covered entity that year. The fallout pushed AMCA into bankruptcy, where a $21 million penalty was suspended.

Investigators led by Connecticut, Florida, Indiana, Illinois, Michigan, and Texas flagged potential HIPAA and consumer protection violations. Labcorp must now write data security requirements into vendor contracts, force collectors to hand over compliance audits, limit how much information it shares, stand up a risk management team, and retain an independent assessor, according to The Record. It also must stop overstating how well it protects personal and health information.

Labcorp separately settled related class action claims for $35 million earlier this year. For health systems, the takeaway is direct: diligence on the vendors that touch patient data is now an enforcement target, not a paperwork exercise.

Share This Article