A coalition of 44 state attorneys general settled a multistate investigation of Laboratory Corporation of America over the 2019 breach at its debt-collection company, the American Medical Collection Agency. Labcorp will pay US$2,287,455, divided among the participating states. The underlying incident was the largest reported that year by a HIPAA-regulated entity: the intruder had access from 1 August 2018 to 30 March 2019, roughly eight months before detection, and the theft affected more than 27.5 million individuals including more than 10.2 million Labcorp patients, spanning names, Social Security numbers, financial information, medical test information and diagnostic codes. AMCA's own settlement — it filed for bankruptcy under remediation costs and paid a US$21 million penalty suspended for financial position — required a security programme, an incident response plan and a CISO. Labcorp's agreement carries injunctive relief: a CISO, security awareness training, an incident response plan that must include a vendor-breach track, internal reporting procedures for vendor incidents, and a bar on misrepresenting its privacy and security posture.
| Attribute | Detail |
|---|---|
| Sector | Healthcare |
| Date | 2026-09-26 |
| Source | HIPAA Journal |
| Reliability | Tier 2 |