44-State Coalition Secures $2.3M Settlement Over Massive Labcorp Data Breach
PUBLISHED Sep 25, 2026, 9:07 AM ET
Read, Watch or Listen
A bipartisan coalition of 44 state attorneys general secured a $2.3 million settlement and strict new data protection safeguards against Labcorp. The legal action follows a massive 2019 cybersecurity breach at American Medical Collection Agency, a third-party debt collection vendor used by Labcorp. The original security intrusion exposed sensitive personal information belonging to more than 27.5 million individuals nationwide. Compromised records included Social Security numbers, payment card details, and confidential medical test diagnostic codes tied to approximately 10.2 million Labcorp patients. Investigators found that the vendor failed to detect the unauthorized access despite multiple warnings from payment processing banks. Under the terms of the settlement announced by New York Attorney General Letitia James, Labcorp must overhaul its vendor risk management protocols. The company is required to enforce rigorous cybersecurity standards on external partners, minimize the sharing of sensitive consumer data, and establish a mandatory internal reporting framework for vendor security incidents.
By Shahbaz A. | JQJO News
Timeline of Events
- On June 3, 2019, American Medical Collection Agency disclosed a major data breach.
- On June 4, 2019, state officials launched multi-state investigations into the security incident.
- On September 25, 2026, a 44-state coalition announced the final settlement agreement.
- Labcorp will implement new vendor risk management protocols in coming months.
- Independent third-party audits will evaluate information security practices over coming years.
- State regulators will monitor compliance with settlement terms throughout upcoming monitoring periods.
- Affected consumers will receive notifications regarding settlement terms and credit monitoring services.
- Future vendor contracts will incorporate mandatory cybersecurity standards across all operations.
- Industry experts anticipate stricter oversight of third-party healthcare debt collection vendors.
- Legal analysts expect similar multi-state coalitions to target vendor security failures.
News Intelligence
- Immediate US impact: Improves corporate cybersecurity standards across major U.S. healthcare providers.
- Possible long-term US impact: Establishes stricter regulatory oversight for third-party vendor data management.
- Most affected groups: Patients, state regulators, and healthcare data security compliance officers.
- Reader priority: Prioritize verified official attorney general statements and legal filings.
- Articles Published:
- 20
- Right Leaning:
- 0
- Left Leaning:
- 0
- Neutral:
- 20
- Distribution:
- Left 0%, Center 100%, Right 0%
Left: Emphasizes corporate accountability and consumer privacy rights protection measures. Center: Focuses on factual settlement terms and legal agreement details. Right: Highlights regulatory compliance and corporate vendor management responsibilities.
Associated Press reported multi-state settlement announcement on September 25, 2026. https://apnews.com/article/labcorp-data-breach-settlement-states-092526
Coverage of Story:
From Left
No left-leaning sources found for this story.
From Center
Labcorp settles 2019 data breach with 44 states for 2.3 million
Associated Press Reuters The Hill Bloomberg Wall Street Journal CNBC USA Today Politico NBC News Washington Post New York Times Forbes Reuters Business Bloomberg Law Security Boulevard Dark Reading SC Media Becker's Hospital Review Fierce Healthcare Modern HealthcareFrom Right
No right-leaning sources found for this story.
Comments