Labcorp AMCA Multistate Data Breach Settlement Finalized, Pays $2.28M
action_required

Labcorp AMCA Multistate Data Breach Settlement Finalized, Pays $2.28M

United States·Briefly Analysis⏱️ 4 min read

Summary

  • Labcorp reached a $2,287,455.00 multistate settlement with 44 attorneys general over the 2019 AMCA data breach.
  • The breach, involving Labcorp's debt collector, potentially exposed personal information of over 27.5 million individuals, including 10.2 million Labcorp patients.
  • The settlement mandates enhanced vendor management and cybersecurity protocols for HIPAA-covered entities, particularly for medical debt collectors.
  • New requirements include developing incident response plans, minimizing data sharing, expanding vendor risk management programs, and hiring a Third-Party Assessor.
  • This resolution underscores the duty of covered entities to protect sensitive data and rigorously oversee third-party vendors.

Multistate Resolution Reached

A central tenet of this Labcorp AMCA multistate data breach settlement is the reinforcement of the principle that HIPAA-covered entities bear a fundamental duty to safeguard personal and protected health information, extending to diligent oversight of vendors entrusted with such data.

The Laboratory Corporation of America (Labcorp) has finalized a multistate settlement with a coalition of 44 attorneys general, including Vermont's Attorney General Charity Clark. This agreement resolves a comprehensive investigation into a significant 2019 data breach that occurred at Retrieval-Masters Creditors Bureau, operating as American Medical Collection Agency (AMCA), a debt collector utilized by Labcorp.

Under the terms of the settlement, Labcorp will disburse a total of $2,287,455.00 to the participating states. Vermont, specifically, is slated to receive $15,533 from this collective payment. This resolution follows a separate settlement reached in 2021 between the multistate coalition and AMCA itself, which occurred after the debt collection company's bankruptcy petition was dismissed.

Extensive Data Exposure

The 2019 security incident at AMCA led to the potential exposure of personal information belonging to more than 27.5 million individuals across the United States. Among those affected were 10.2 million patients of Labcorp, with 948 Vermont residents specifically identified as having their data compromised. The breach involved sensitive personal details entrusted to the debt collector, highlighting critical vulnerabilities in third-party vendor security.

This widespread exposure underscored the urgent need for enhanced data protection measures and more rigorous oversight of third-party service providers, particularly those handling protected health information.

Heightened Vendor Management Standards

A central tenet of this Labcorp AMCA multistate data breach settlement is the reinforcement of the principle that HIPAA-covered entities bear a fundamental duty to safeguard personal and protected health information, extending to diligent oversight of vendors entrusted with such data. The agreement introduces robust new requirements for vendor management, with a particular focus on medical debt collection agencies. These mandates include developing specific elements of the company's information security program, such as an incident response plan that incorporates internal reporting mechanisms for vendor security events.

Furthermore, the settlement obliges Labcorp to minimize the sharing of data with vendors, while carefully balancing the legitimate needs of debt collectors to fulfill their legal obligations. The company must also expand its vendor risk management program to encompass a dedicated team, employ specialized tools for vendor evaluation, and verify vendor compliance. For debt collectors, a specialized subset of vendors, additional stringent requirements are imposed: maintaining comprehensive contract inventories, enforcing cybersecurity standards through contractual agreements, segmenting data often aggregated by collectors for multiple clients, and mandating that debt collectors perform regular assessments and audits. The agreement also grants the right to terminate contracts for non-compliance. Finally, Labcorp is required to engage a Third-Party Assessor to conduct an information security assessment, with a specific emphasis on vendor risk management, ensuring comprehensive adherence to these new standards.

A Precedent for Data Security

This Labcorp data breach resolution sets a significant precedent, emphasizing the critical importance of robust vendor security and management for entities handling sensitive personal and health information. The comprehensive nature of the new requirements, particularly for medical debt collector cybersecurity, underscores a heightened expectation for proactive data protection measures and stringent oversight throughout the entire data processing ecosystem.

The multistate AG data breach settlement involved a broad coalition of states, demonstrating a unified regulatory stance on vendor security. Joining Attorney General Clark were the attorneys general from Alaska, Alabama, Arizona, Arkansas, Colorado, Connecticut, the District of Columbia, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Michigan, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and West Virginia.

Practical Implications

This settlement reinforces the heightened duty of HIPAA-covered entities to implement robust vendor management and cybersecurity protocols, particularly for medical debt collectors. Legal and compliance teams should review their vendor contracts and information security programs to ensure alignment with these new, stringent requirements to mitigate data breach risks and regulatory penalties.

Source

Source: Original reporting via Vermont Attorney General's office

Get Deeper AI analysis

How does this affect you?

Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.

Finish Reading the Full Story and the Expert Analysis.

Get the latest legal & regulatory intelligence in United States

Instant access to full analysis, cited statutes & expert commentary
Customize your dashboard to track what matters to your business operations

Already have an account? Log in

Wansom is AI and can make mistakes.