Labcorp will pay nearly $2.3 million to states and tighten oversight of debt collectors after a breach of one of its vendors' systems potentially exposed information about millions of patients. New York will receive $89,178 under the multistate settlement.
The settlement announced by New York Attorney General Letitia James follows a 2018-19 intrusion at American Medical Collection Agency, or AMCA, which collected medical debts for Labcorp. The attorney general's office says information associated with more than 27.5 million people nationwide was potentially exposed, including 10.2 million Labcorp patients and about 420,000 New Yorkers.
What investigators found
According to James' office, a hacker accessed AMCA's internal system from Aug. 1, 2018, through March 30, 2019. The potentially exposed records included Social Security numbers, payment-card information, names of medical tests and diagnostic codes.
The release says banks that processed AMCA payments warned of a possible breach, but the debt collector did not detect the intrusion. AMCA is based in Elmsford, New York. Labcorp, based in North Carolina, provides diagnostic laboratory testing.
James and 43 other attorneys general reached the settlement with Labcorp. The company will pay $2,287,455 in total to the states; the New York portion is $89,178. The agreement follows a separate 2021 multistate settlement with AMCA that included a $21 million payment suspended because of that company's bankruptcy.
New requirements for Labcorp and debt collectors
The settlement requires Labcorp to improve its information-security program and establish an incident-response plan that includes internal reporting of vendor breaches. It must also limit the data it shares with vendors while allowing debt collectors to meet legal obligations.
Labcorp must expand its vendor-risk program with a dedicated team, tools to assess vendors and checks of their compliance. Debt-collector contracts must include cybersecurity standards and a way for Labcorp to terminate agreements for noncompliance.
The requirements also call for separating data that collectors may hold for multiple clients and for assessments and audits of those collectors. A third-party assessor will review Labcorp's information security, with particular attention to vendor management.
James said medical information warrants strong safeguards. The settlement describes changes intended to reduce future risk; the release does not say the agreement can reverse exposure from the earlier breach or identify every person whose records were accessed.



