Labcorp Settled Multistate Data Breach Claims
The diagnostics firm finalized a $2.2 million deal with 40 states following a 2019 incident.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Should companies be held strictly liable for data breaches that occur through their third-party vendors?
Labcorp reached a $2.2 million settlement with 40 states to resolve investigations into a 2019 data breach that exposed the personal information of 10 million individuals. The company also agreed to a separate $35 million class action settlement.
Why it matters
The agreement highlights the ongoing legal and financial repercussions for large healthcare entities following significant cybersecurity failures. It mandates stricter vendor data protocols to mitigate risks in the medical billing and collections ecosystem.
The settlement covers a 2019 breach affecting 10 million people, including 400,000 residents in New Jersey and 200,000 in Pennsylvania. New Jersey will receive $68,000 from the agreement, while Pennsylvania is allocated $43,000.
The players
Labcorp
A global diagnostics and drug development company that provides laboratory testing services for healthcare providers.
The details
To prevent future exposures, Labcorp committed to minimizing the volume of sensitive data shared with third-party vendors. The company is also implementing enhanced cybersecurity requirements for debt collection agencies that process its patient data.
Timeline
2019: The data breach occurred.
September 24, 2026: The settlement with 40 states was announced.
The Tech Race
This settlement follows a pattern of state-level legal enforcement actions used to penalize entities for failing to secure patient data as required by federal privacy statutes. It reflects the broader trend of states utilizing local consumer protection laws to address healthcare-related cybersecurity negligence.
Individuals whose data was exposed in the 2019 breach may be eligible for compensation through the separate $35 million class action settlement. Affected residents should monitor their financial and medical records for unauthorized activity as standard practice following such disclosures.
The takeaway
The case underscores the lasting legal liability organizations face when patient data is compromised by third-party debt collection vendors. Users should watch for updates on the $35 million class action claim process for potential compensation eligibility.
Further reading
For more context on how regulatory bodies handle information leaks, visit the Cybersecurity section.
Live Poll
Should companies be held strictly liable for data breaches that occur through their third-party vendors?









