Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Reported by
- 1 outlet
A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for a $2.3 million fine and a promise of sweeping data security reforms in the wake of a 2019 data breach that impacted 10.2 million customers.
The data breach originated with security failings at American Medical Collection Agency (AMCA), a debt collector that Labcorp worked with. The attorneys general contended that Labcorp should have don’t more to police AMCA, after the incident there impacted a total of 27.5 million people nationwide.
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
Labcorp must also include cybersecurity requirements in vendor contracts and mandate that data collectors routinely provide the medical testing giant with audits documenting their compliance with the new rules.
It must also retain an independent expert to conduct information security assessments and begin siloing data that debt collectors often aggregate for several clients at once.
In 2021, a court sided with the coalition of attorneys general suing AMCA and ordered the debt collector pay a $21 million fine that was suspended because the company went bankrupt.
“Millions of patients’ private health information was potentially exposed because of Labcorp’s failures to protect its customers,” New York Attorney General Letitia James said in a statement Thursday. “As a result of our investigation, Labcorp will make critical changes to protect patients and prevent this kind of data breach from happening again.”
A Labcorp spokesperson did not immediately respond to a request for comment and the company did not issue a press release about the settlement.
Reproduced in full under licence from The Record. © The Record.
Fastnexa security experts
Dealing with this in your own company?
If this story touches software, suppliers or systems you use, a Fastnexa security expert can tell you what it means for you and what to do first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-25 19:35 UTC
Related stories
- New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
SecurityWeek · 2026-09-26
- Supreme Court permits states to use SAVE database for citizenship checks
CyberScoop · 2026-09-25
- Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
SecurityWeek · 2026-09-24
- 3 Cyber Threats That Defined the Summer of 2026
Dark Reading · 2026-09-24
- FedRAMP VDR & VER: Daily Scans Are Only the Beginning
BleepingComputer · 2026-09-24