Labcorp will pay $2,287,455 and rebuild how it vets every vendor with access to patient data, under a settlement with attorneys general from 43 states and the District of Columbia announced this week. The case traces back to a 2019 breach at American Medical Collection Agency, a debt collector Labcorp had used since 1996, that exposed roughly 10.2 million Labcorp patients among 27.5 million people nationwide.
Labcorp itself was never breached. AMCA was. The settlement, filed as an Assurance of Voluntary Compliance, holds Labcorp responsible anyway, for inadequate oversight of a vendor it kept sending patient data to for over two decades without, prosecutors allege, verifying AMCA’s controls kept pace with what it handled. The required reforms go beyond a policy update: Labcorp must stand up a Vendor Risk Management Team reporting to the CISO at least quarterly, assign every debt collector a documented risk rating tied to the health data it receives, run recurring third-party audits rather than one-time questionnaires, and wall off debt collectors from data they do not strictly need.
Why it matters for the security leader: this settlement effectively writes a vendor-risk operating model into a binding legal document, not a best-practice guide. Any healthcare-adjacent company treating vendor security as a contract clause rather than an ongoing, staffed, audited program is looking at the same exposure Labcorp just paid for, minus the seven-year gap between breach and resolution.
The original insight is the size of the gap itself. AMCA’s breach became public in June 2019. This settlement, with its effective date of October 1, 2026, arrives more than seven years later. A vendor risk program built today, in response to this settlement, would have protected data that was exposed under a Labcorp contract signed in 1996. The regulatory consequence for a named vendor failure is real, but it runs on a clock too slow to be the primary defense against it.
Prior CyberTech coverage: A Vendor’s Stolen Credentials Exposed Veradigm Patient Data and A Shipping Vendor Kept Data Trezor Thought Was Gone.