Labcorp Settled With 44 States Over 2019 Data Breach

The agreement concludes a multistate investigation into the mishandling of patient information by a third-party vendor.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration featuring a central metallic vault and interlocking blocks, symbolizing systemic data security and vendor risk management.
Labcorp reached a $2.3 million settlement with 44 states to resolve a 2019 data breach involving patient information mishandled by a third-party billing vendor. AI Illustration. Upload story photo >

Live Poll

Should corporations be held legally liable for data breaches caused by their third-party vendors?

Alaska and 43 other states have reached a $2.3 million settlement with Labcorp regarding a 2019 data breach at the American Medical Collection Agency. The incident exposed the sensitive personal data of 10.2 million Labcorp patients, including 82,958 Alaskans.

Why it matters

The settlement addresses systemic failures in corporate oversight of third-party vendors handling sensitive medical data. It forces new security mandates on Labcorp to limit data sharing and improve incident response, signaling a tighter regulatory approach to vendor risk management.

Labcorp will pay $2,287,455 to the multistate coalition to resolve claims stemming from a breach that exposed the data of 10.2 million patients nationwide. Alaska residents account for 82,958 of those affected, with the state receiving $26,010 as part of the agreement.

The players

Labcorp

A global life sciences company that provides clinical laboratory services and diagnostic testing data.

American Medical Collection Agency

A debt collection firm that processed billing for healthcare providers and experienced a massive data breach.

Cori Mills

The Acting Attorney General of Alaska who oversaw the state's participation in the multistate settlement.

The details

The breach occurred after Labcorp transferred patient data to the American Medical Collection Agency—a third-party firm hired to manage outstanding customer bills—which lacked sufficient security. The settlement requires Labcorp to implement a strict vendor risk management program and appoint a third-party assessor to verify ongoing information security protocols. These measures aim to minimize the volume of data shared with external vendors and establish a formal incident response plan for potential future threats.

Timeline

  1. 2019: The data breach occurred at the American Medical Collection Agency.

  2. 2021: A multistate coalition reached a settlement with the American Medical Collection Agency.

  3. September 29, 2026: Acting Attorney General Cori Mills announced the Labcorp settlement.

The Tech Race

This settlement follows the precedent set by the 2021 multistate coalition settlement with the American Medical Collection Agency regarding institutional liability for third-party security failures. It shifts the burden of proof further toward primary data controllers to secure their supply chains.

The agreement mandates that Labcorp minimize the amount of data shared with vendors, which may change the administrative processes for patients with outstanding bills. While the settlement process is now resolved for these states, patients should continue to monitor their credit for any activity related to the 2019 breach.

The takeaway

This settlement highlights the growing legal risk for companies that outsource data handling to third-party vendors. Readers should monitor the ongoing class action lawsuits involving other entities impacted by the American Medical Collection Agency for further developments.

Further reading

Find more on how regulators are managing digital threats in the Cybersecurity section.

Source note: This article includes information reported by Alaska Native News.

Live Poll

Should corporations be held legally liable for data breaches caused by their third-party vendors?