Labcorp has agreed to pay $2,287,455 to states and revise how it controls patient data shared with outside debt collectors under a multistate Labcorp data breach settlement announced September 24. The agreement follows a 2019 intrusion at American Medical Collection Agency, or AMCA, a debt collector used by the laboratory company.
New York Attorney General Letitia James said a bipartisan group of 44 attorneys general, New York plus 43 others, secured the settlement. The breach potentially exposed personal information belonging to more than 27.5 million people nationwide, including 10.2 million Labcorp patients, according to New York and Colorado attorney general releases.
The states are making a specific point about responsibility: the compromised system belonged to AMCA, not Labcorp. But the settlement focuses on Labcorp's controls over a vendor that received its customers' data. Colorado Attorney General Phil Weiser said companies cannot transfer their data-security legal obligations to contractors or other third parties.
What must Labcorp change under the data breach settlement?
Labcorp must build vendor-security controls into its information-security program. The requirements target the fairly ordinary but consequential mechanics of sharing patient information with debt collectors: what data leaves the company, what contractual rules govern it, and how Labcorp verifies that a vendor is following them.
- Create an incident-response plan that includes internal reporting of vendor security events.
- Reduce data shared with vendors where appropriate, while accounting for debt collectors' legal obligations.
- Expand its vendor-risk program with a dedicated team, tools to evaluate vendors, and processes to verify compliance.
- Require cybersecurity standards in debt-collector contracts, maintain contract inventories, and reserve the right to terminate vendors that do not comply.
- Require debt collectors to conduct assessments and audits, and segment data that collectors may otherwise aggregate for multiple clients.
- Hire an independent third-party assessor to review information security with a focus on vendor-risk management.
According to the New York attorney general's office, a hacker accessed AMCA's internal systems between August 1, 2018, and March 30, 2019. The information potentially exposed included Social Security numbers, payment-card data, and the names of medical tests and diagnostic codes. New York said approximately 420,000 state residents were affected; Colorado reported 130,522 residents in that state.
How does this deal relate to the earlier AMCA case?
The $2,287,455 payment goes to the participating states, rather than to affected patients. New York said it will receive $89,178, while Colorado said it expects $32,086.
It is separate from the coalition's 2021 settlement with AMCA, which included a $21 million payment that was suspended because of the collector's bankruptcy, according to New York. Colorado also said Labcorp agreed to a separate $35 million settlement in related class-action litigation; that litigation remains ongoing for other AMCA client covered entities.
Neither state release says Labcorp admitted wrongdoing. The agreement instead sets the payment and vendor-management changes demanded by the state regulators after their investigation.
This story draws on original reporting from The Record.