• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
Clever Dude Personal Finance & Money

Clever Dude Personal Finance & Money

Family, Marriage, Finances & Life

  • Toolkit
  • Contact
  • Lunch
  • Save A Ton Of Money
  • About Clever Dude
  • Our Editorial Commitment

News

Labcorp to Pay $2.3 Million After Data Breach Exposed Information of 10.2 Million Patients

September 25, 2026
By Daniel Webster
- Leave a Comment
Labcorp data breach settlement
Labcorp will pay approximately $2.3 million to 44 states and make major changes to its vendor-security practices following an investigation into a 2019 third-party data breach that potentially affected 10.2 million Labcorp patients nationwide. Jennie Book/Shutterstock

Labcorp will pay approximately $2.3 million and make significant changes to how it protects patient information shared with outside vendors following an investigation into a massive 2019 data breach involving a third-party medical debt collector.

New York Attorney General Letitia James announced September 24 that New York had joined a bipartisan coalition of 43 other attorneys general in reaching the agreement with Laboratory Corporation of America, better known as Labcorp. According to the New York Attorney General’s announcement, the underlying breach potentially exposed personal information belonging to more than 27.5 million people nationwide.

Approximately 10.2 million of those affected were Labcorp patients, including about 420,000 New Yorkers.

Importantly, the hacker did not directly breach Labcorp’s own computer systems in this incident. Instead, the intrusion occurred at American Medical Collection Agency, or AMCA, a third-party debt collector that Labcorp used to collect certain unpaid patient balances.

Hacker Had Access for Months

AMCA, based in Elmsford, New York, specialized in collecting small-balance medical debts for laboratories and medical testing facilities.

According to the Attorney General’s investigation, a hacker gained access to AMCA’s internal system beginning August 1, 2018, and remained able to collect customer information until March 30, 2019.

The investigation also found that AMCA failed to detect the intrusion despite receiving multiple warnings from banks that processed its payments about a potential breach.

The New York Attorney General says information potentially exposed in the breach included Social Security numbers, payment-card information, names of medical tests and diagnostic codes.

Labcorp previously disclosed that its own systems were not affected by the AMCA incident and that it stopped sending new collection requests to AMCA after learning about the breach. The company also previously said it offered 24 months of free credit monitoring and identity-protection services to individuals whose Social Security numbers were affected.

Labcorp Must Pay More Than $2.28 Million

Under the new multistate agreement, Labcorp will pay a total of $2,287,455 to the participating states.

New York will receive $89,178 of that amount.

But the settlement goes considerably further than a financial payment. The states are requiring Labcorp to make changes intended to reduce the risk that sensitive patient information entrusted to outside companies will be exposed in another breach.

Those requirements are particularly relevant because a company’s cybersecurity risk doesn’t end when information leaves its own computer network.

Labcorp Must Change How It Handles Third-Party Vendors

Under the settlement, Labcorp must improve its information-security program and create an incident-response plan that addresses security breaches involving vendors.

The company must also minimize the amount of information it shares with vendors while balancing the information debt-collection companies need to satisfy their legal obligations.

Labcorp’s vendor-risk-management program must be expanded to include a dedicated team, vendor-assessment tools and procedures for verifying vendors’ compliance with security requirements.

Debt-collection companies handling Labcorp information will face additional requirements, including contractual cybersecurity standards, assessments and audits. Labcorp must also address how patient data is segmented when a collection company handles information belonging to multiple clients and include provisions allowing contracts to be terminated for noncompliance.

The agreement additionally requires Labcorp to hire an independent third party to conduct an information-security assessment focused specifically on vendor risk management.

The AMCA Breach Previously Led to a Separate Settlement

This isn’t the first multistate action arising from the AMCA breach.

In 2021, New York and other states reached a separate agreement with AMCA itself. That settlement included a $21 million payment that was suspended because AMCA had filed for bankruptcy.

The latest agreement focuses instead on Labcorp’s responsibility for protecting patient information when that information is shared with outside vendors.

For consumers, that distinction matters. A company doesn’t necessarily need to suffer an intrusion on its own network for customer information it collected to become exposed; vendors, payment processors, debt collectors and other third parties can also become points of vulnerability.

What Former Labcorp Patients Should Know

The settlement announcement doesn’t say that all 10.2 million Labcorp patients affected by the 2019 incident suffered identity theft or financial losses. It also doesn’t announce a new consumer compensation fund or instruct former patients to submit claims for a portion of the $2.3 million settlement.

Consumers therefore should be cautious about messages claiming they must provide banking information, pay a fee or click a link to collect money from this particular settlement.

Anyone concerned about information exposed in an old breach can still take basic identity-protection steps, including reviewing credit reports for unfamiliar accounts, monitoring financial statements and considering a credit freeze if Social Security information may have been compromised.

Consumers can obtain information about placing and removing a credit freeze through the Federal Trade Commission’s IdentityTheft.gov resources, and anyone who discovers evidence of identity theft can use the site to create a recovery plan.

The Labcorp settlement provides another reminder that sensitive information can remain vulnerable even after a company hands it to an outside contractor. For consumers, the 2019 breach may be old news, but for Labcorp, the resulting security obligations are continuing years later.

What to Read Next

HOAs That Don’t File Properly Lose Their Right to Collect Attorney’s Fees or Interest on Delinquent Accounts

Amway and Affiliates Agree to $225 Million Settlement Over Earnings and Recruiting Claims

TikTok and ByteDance Agree to $400 Million Settlement Over Children’s Privacy Allegations

Related Posts

  • 11 Relationship Patterns Men Pick Up on That Actually Hold True
    11 Relationship Patterns Men Pick Up on That Actually Hold True

    Some patterns in relationships don’t just exist in someone’s head—they show up again and again,…

  • Some Hidden Cybersecurity Risks Are Targeting Men In Their 30s And 40s
    8 Hidden Cybersecurity Risks Targeting Men In Their 30s And 40s

    Scrolling through your phone after a long day, checking emails, or catching up on social…

  • relationship
    8 Signals That She Sees You as Just Average

    Everyone wants to feel special in a relationship. The fear of being seen as just…

  • 8 MORE random things about me
    8 MORE random things about me

    Don't worry, I won't tag anyone this time. I decided that I had some more…

  • How I'm Using Jeans To Teach My Son About Finances

    My son is extremely picky about his jeans. I dread going shopping for new jeans…

  • These Are 8 Tax Write-Offs That Are Instant Red Flags for 2026
    8 Tax Write-Offs That Are Instant Red Flags for 2026

    Taxes are one of the few things in life that can feel both boring and…

Daniel Webster - penname of an anonymous District Media writer

About Daniel Webster

Daniel Webster is a personal finance writer and editor with extensive experience overseeing content strategy and quality standards across multiple high-traffic money sites. With over ten years of writing and editing experience, Daniel focuses on clear, practical guidance covering budgeting, debt, spending, and building long-term financial security.

Daniel's work prioritizes accuracy, usefulness, and reader trust—standards developed through years of hands-on editorial leadership in consumer finance publishing. Daniel’s contributions emphasize actionable advice that helps people make better decisions with their money.

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Most Popular Articles

Are you feeling the call to be a Clever Dude? Then, let's get down to brass tacks and explore what it takes to be one. Get ready for an in-depth look into the anatomy of someone who exudes cleverness!

There's nothing like hearing you're clever; it always hits the spot!

Footer

  • Toolkit
  • Contact
  • Lunch
  • Save A Ton Of Money
  • About Clever Dude
  • Our Editorial Commitment

Copyright © 2006–2026 District Media, Inc. All Rights Reserved. Contact Us