Labcorp to Pay $2.3 Million and Overhaul Security After Massive Data Breach
A coalition of 44 state attorneys general has settled a lawsuit against medical testing giant Labcorp over a 2019 data breach that exposed the information of 10.2 million customers. The breach originated with American Medical Collection Agency (AMCA), a debt collector Labcorp worked with, and officials say Labcorp did not do enough to oversee AMCA's security practices. As part of the settlement, Labcorp will pay a $2.3 million fine.
Beyond the fine, Labcorp has agreed to a series of security reforms. These include building an incident response plan specifically for vendor security failures, limiting the amount of data shared with vendors, and creating a risk management team to track vendor compliance. Labcorp must also add cybersecurity requirements into vendor contracts, require regular compliance audits from data collectors, hire an independent expert for security assessments, and separate data that is often pooled together across multiple clients.
The case highlights the risks businesses face when third-party vendors mishandle sensitive data. AMCA itself was previously ordered to pay a $21 million fine over the same breach, though that penalty was suspended after the company went bankrupt. New York Attorney General Letitia James said the settlement will force Labcorp to make changes needed to protect patients and prevent similar incidents.