Labcorp Settles Multistate AMCA Data Breach Investigation for $2.3M
Labcorp has agreed to pay a financial penalty of $2.3 million and strengthen its information security program to settle a multistate investigation of a 2019 data breach at its debt collection company that affected approximately 10.2 million Labcorp patients.
Labcorp is a Burlington, North Carolina-based life sciences and healthcare company that provides medical laboratory testing and diagnostics services for healthcare providers. Labcorp contracted with American Medical Collection Agency (AMCA), a subsidiary of Retrieval-Masters Creditors Bureau (RMCB), to retrieve outstanding customer debts related to its medical testing services. AMCA was provided with the personal information (PI) and protected health information (PHI) of Labcorp patients to fulfil its contracted duties.
On March 19, 2019, RMCB identified suspicious activity within the AMCA network, and the forensic investigation determined that a hacker had access to AMCA systems for around 8 months, from August 1, 2018, to March 30, 2019. The hacker exfiltrated files containing PI and PHI, including names, Social Security numbers, financial information, diagnosis codes, and medical test information. Many AMCA clients were affected, and the PI and PHI of more than 27.5 million individuals was potentially stolen in the incident. It was the largest healthcare data breach at a HIPAA-regulated entity that year and still ranks as one of the largest healthcare data breaches of all time.
AMCA was investigated by a coalition of more than 40 state attorneys general, who identified multiple security failures. The $21 million multistate settlement to resolve the investigation was suspended due to the company’s financial position. The coalition of 44 state attorneys general also investigated Labcorp. The investigation, led by the Connecticut, Florida, Indiana, Illinois, Michigan, and Texas attorneys general, identified security failures at Labcorp that potentially violated the Health Insurance Portability and Accountability Act (HIPAA) and state laws.
“Labcorp outsourced their debt collection, and they shared sensitive personal information for millions of patients that was ultimately compromised. Labcorp was responsible for vetting and managing that vendor, and we’re holding them accountable,” said Connecticut Attorney General William Tong.
Labcorp agreed to settle the investigation and agreed to a payment of $2,287,455, which will be divided between the states participating in the action. In addition, Labcorp agreed to injunctive relief, which includes significant improvements to its information security program, with specific requirements for vendor risk management and debt collectors.
The requirements include expanding its information security program to include vendor risk management, which must be overseen by a dedicated vendor risk management team. A Chief Information Security Officer must be appointed to oversee its information security program.
Vendors must be vetted using risk assessment tools, and vendors’ compliance must be verified. Labcorp must restrict the information shared with vendors such as debt collection companies. Data must be limited to the minimum necessary information to allow the debt collector to perform their contracted duties. There are specific requirements for debt collectors as a subset of vendors, which include maintaining contract inventories, enforcing contractual cybersecurity standards, and data segmentation. Debt collectors must also perform security assessments and undergo annual audits.
Labcorp must also update its incident response plan with specific requirements for vendor security incidents, including internal reporting of incidents to senior management. Labcorp must also engage a third-party assessor to conduct a security risk assessment, with a specific focus on vendor risk management. This is the second Labcorp settlement related to the AMCA data breach. Earlier this year, Labcorp agreed to settle class action litigation for $35,000,000.
