Skip to content

Labcorp pays $2.3 mn over AMCA breach affecting 10.2 mn patients

Labcorp pays $2.3 mn over AMCA breach affecting 10.2 mn patients

Labcorp has agreed to pay $2.3 mn to resolve a multistate investigation into a 2019 data breach at its medical debt collection vendor that potentially exposed information belonging to 10.2 mn Labcorp patients.

The settlement involves a bipartisan coalition of 44 attorneys general and concerns Labcorp’s use of Retrieval-Masters Creditors Bureau, which operated as American Medical Collection Agency, or AMCA. Labcorp transferred patient information to AMCA for collection of outstanding medical bills.

The breach occurred at AMCA and potentially exposed personal information belonging to more than 27.5 mn people across the U.S. Of those, 10.2 mn were Labcorp patients. Maryland alone had 451,558 affected residents, while 82,958 Alaska residents and 43,666 Connecticut residents were among those potentially affected.

States focus on Labcorp’s vendor oversight

The attorneys general examined Labcorp’s responsibility for information shared with outside vendors even though the breach occurred on AMCA systems. Their position is that companies remain responsible for protecting sensitive information when collection or other functions are outsourced.

Marylanders trust healthcare companies to protect their most sensitive medical information, even when that information is shared with outside vendors.

Maryland Attorney General Anthony G. Brown

G. Brown said the agreement requires Labcorp to maintain stronger oversight of vendors handling patient data.

Connecticut Attorney General William Tong said Labcorp remained responsible for vetting and managing the debt collector after sharing sensitive information belonging to millions of patients. The settlement applies that position to HIPAA-covered entities handling personal information and protected health information through outside vendors.

Labcorp must expand vendor security controls

The settlement requires Labcorp to change parts of its information security and vendor risk management programs. Its incident response procedures must cover security events involving vendors, while the company must reduce the amount of data shared with outside providers where possible.

Labcorp must maintain a dedicated vendor risk management team, use tools to evaluate outside providers and verify compliance with security requirements.

Medical debt collectors face additional contractual controls because they often process large volumes of patient information.

Those debt collectors must maintain contract inventories and meet cybersecurity requirements written into their agreements.

Labcorp must also require data segmentation when collectors hold information belonging to multiple clients, conduct security assessments and audits, and retain the right to terminate vendors for non-compliance.

An independent third-party assessor will perform an information security review focused on vendor risk management. The requirements are intended to reduce exposure created when patient information moves beyond Labcorp’s own systems.

Settlement follows AMCA bankruptcy

The coalition previously reached a settlement with AMCA in 2021 after the debt collector’s bankruptcy petition was dismissed. That agreement included a $21 mn payment that was suspended because of AMCA’s financial condition.

Labcorp will pay $2,287,455 to the participating states under the new agreement. Connecticut will receive $81,296, while Alaska will receive $26,010. Maryland also participated on the executive committee that assisted the states leading the investigation.

The investigation was led by the attorneys general of Connecticut, Florida, Indiana, Illinois, Michigan and Texas. Maryland, Massachusetts, New York, North Carolina and Tennessee served on the executive committee, with attorneys general from other participating states and the District of Columbia joining the settlement.

Separate $35 mn class action settlement

The regulatory agreement is separate from private litigation arising from the same breach. Labcorp has also agreed to a $35 mn settlement in a related class action, while litigation involving other AMCA clients continues.

The 2019 incident shows the exposure created when healthcare companies send patient information to outside billing and collection providers.

Under the settlement, Labcorp must apply more direct security controls to those relationships rather than relying on vendors to manage patient data independently.

The coalition leading the investigation involved Raoul and the attorneys general of Connecticut, Florida, Indiana, Michigan and Texas, with assistance from a committee made up of the attorneys general of Maryland, Massachusetts, New York, North Carolina and Tennessee.

The attorneys general of Alaska, Alabama, Arizona, Arkansas, Colorado, the District of Columbia, Delaware, Georgia, Hawaii, Idaho, Iowa, Kansas, Kentucky, Maine, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Utah, Vermont, Virginia, Washington, Wisconsin and West Virginia also joined in the settlement.