44 State AGs Settle With Labcorp Over 2019 AMCA Data Breach
Independently fact-checked against primary sources (last audited September 25, 2026). · 7 primary sources cited on this page. How we verify our legal content

Forty-four state attorneys general announced a settlement on September 24, 2026 with Laboratory Corporation of America Holdings over the 2019 American Medical Collection Agency breach. Labcorp will pay $2,287,455 to the states and rebuild how it vets the vendors that handle patient data.
Information last verified on September 25, 2026. This is a developing story; we update it as the record changes.
Status: Entered. This is a multistate attorney general enforcement settlement, signed as an Assurance of Voluntary Compliance and announced on September 24, 2026, with an effective date of October 1, 2026. The $2,287,455 is paid to the participating states, not to consumers. It creates no consumer claim, no claim form and no individual payout.
Jurisdiction scope: Forty-four jurisdictions signed, including the District of Columbia. Connecticut, Florida, Illinois, Indiana, Michigan and Texas led the investigation, with an executive committee of Maryland, Massachusetts, New York, North Carolina and Tennessee. Seven states did not sign: California, Louisiana, Mississippi, Montana, North Dakota, South Dakota and Wyoming. Forty-three states plus the District of Columbia makes the 44 signatories. The settlement binds Labcorp nationally as a matter of its own compliance program, but only signatory attorneys general released claims and only they can enforce it.
What Happened
American Medical Collection Agency was the trade name of Retrieval-Masters Creditors Bureau, a debt collector that chased unpaid medical bills for laboratories and hospitals. Labcorp first contracted with AMCA in 1996, according to the settlement document, and sent it patient billing data for collection.
AMCA told Labcorp that an unauthorized user appeared to have had access to AMCA's systems between August 1, 2018 and March 30, 2019, according to Labcorp's SEC filings. AMCA notified Labcorp of the incident on May 14, 2019, according to Labcorp's SEC filings, and Labcorp publicly announced the breach on June 4, 2019, the date the settlement document uses. The Connecticut Attorney General's office puts the nationwide exposure at more than 27.5 million individuals across all of AMCA's clients, including 10.2 million Labcorp patients. Connecticut counted 43,666 affected residents, Pennsylvania roughly 218,408, and Delaware 115,250.
AMCA itself filed for bankruptcy. The multistate coalition settled with AMCA in 2021, after that bankruptcy petition was dismissed, for a payment that was suspended because the company could not pay it. That left the question the states have now answered against Labcorp: what does the company that handed over the data owe when its contractor is the one that gets breached?
The document signed here is an Assurance of Voluntary Compliance, the instrument state attorneys general use to close a consumer protection investigation without filing suit. Connecticut signed on September 11, 2026 and Labcorp on September 18, 2026. It becomes effective October 1, 2026, and Connecticut's $81,296 share is due within 30 days of that date, or within 30 days of final approval where state law requires a court to approve the agreement. Delaware's allocation is $30,135 and Pennsylvania's is $43,313, which gives a sense of how the total is split by resident count rather than evenly.
Labcorp does not concede anything. Paragraph 35 states that nothing in the agreement is "an admission or concession or evidence of any liability or wrongdoing whatsoever," and that it is entered "for settlement purposes only."
What Labcorp Agreed to Do
The money is the small part. The operative section runs 20 paragraphs of injunctive relief, paragraphs 4 through 23, and nearly all of it is about controlling contractors.
Program and people. Within 120 days of the effective date, and annually after that, Labcorp must review and update its information security program. It must employ a chief information security officer with real credentials who advises the CEO and the board on security posture and risk. Security awareness and privacy training must reach everyone whose job touches patient personal information or protected health information within 180 days, then annually, and new hires within 30 days.
Incident response and internal escalation. The security program must include an incident response plan that specifically covers the handling, investigation and reporting of what the agreement calls a Vendor Security Event, defined as a compromise at a vendor affecting the data of at least 500 Labcorp consumers. Labcorp must have a process for escalating those events to senior management or the board. The agreement is careful to add that this internal process does not substitute for the company's legal notification duties.
Sharing less data. Labcorp must limit what it discloses to vendors to the minimum necessary for the purpose, and must write policies specific to debt collectors. Two are concrete: a process to give a debt collector only the additional information needed when a consumer disputes a debt and asks for verification, and a process requiring debt collectors to confirm in writing each year that they have deleted or destroyed consumer data once a debt is satisfied or the referral is withdrawn.
Vendor risk management. Labcorp must maintain a written vendor risk management program, review it at least annually, and staff a dedicated vendor risk management team with security, risk or audit experience that reports to the CISO at least quarterly. Vendor assessments must be scaled to a documented risk rating, and where Labcorp uses security questionnaires it must corroborate the answers rather than filing them.
Debt collector contract terms. This is the most prescriptive part. Labcorp must keep an inventory of its debt collector contracts recording what data each one holds and when it was last assessed. By contract, each debt collector must adopt a recognized cybersecurity framework such as the NIST Cybersecurity Framework, segment Labcorp data from other data in shared environments, dispose of data to NIST standards, protect cryptographic keys properly, and remediate critical vulnerabilities flagged by US-CERT. Each must run annual risk assessments and annual penetration tests and provide attestations. Each must undergo an annual SOC 2 Type 2 audit, a bi-annual HITRUST CSF validated assessment, or a reasonable equivalent. Contracts must spell out who notifies consumers after a vendor breach, and Labcorp must retain the right to act against a non-compliant collector up to terminating the contract. Existing contracts must be amended to include these terms within 12 months.
Independent verification. Within 18 months, Labcorp must obtain an assessment from an independent third-party assessor holding a CISSP or equivalent certification with at least five years of experience evaluating vendor risk management. The assessor reports to the Connecticut Attorney General within 60 days of completing the work, and other signatory states can request a copy. Connecticut will treat the report as exempt from public records disclosure.
Paragraph 30 sets the clock: the obligations in paragraphs 9 through 22, which is most of the vendor and debt collector machinery, expire five years after the effective date.
What the Law Actually Says
The spine of this case is a principle worth stating plainly: handing data to a contractor does not hand off responsibility for it.
The attorneys general built that on three stacked bodies of law, listed in Appendix A of the agreement state by state. First, each state's unfair and deceptive acts and practices statute, from the Connecticut Unfair Trade Practices Act at Conn. Gen. Stat. 42-110b to the Texas Deceptive Trade Practices Consumer Protection Act at Tex. Bus. & Com. Code 17.41 through 17.63. Second, each state's breach notification or personal information protection act, such as the Illinois Personal Information Protection Act at 815 ILCS 530/1 or the Florida Information Protection Act at Fla. Stat. 501.171. Those statutes impose duties both to safeguard personal information and to notify residents when it is compromised, and they are the everyday backbone of US data privacy laws at the state level. Coverage and thresholds differ enough between states that the practical picture only emerges from a state-by-state privacy law comparison.
Third, and most important to the vendor theory, HIPAA. Labcorp is a covered entity. AMCA, as a debt collector processing patient billing data on its behalf, was a business associate as that term is defined at 45 CFR 160.103. Under 45 CFR 164.308(b)(1), a covered entity may let a business associate handle electronic protected health information "only if the covered entity obtains satisfactory assurances, in accordance with 164.314(a), that the business associate will appropriately safeguard the information." The parallel privacy rule provision at 45 CFR 164.502(e)(2) requires those assurances to be "documented through a written contract or other written agreement or arrangement." The minimum necessary standard at 45 CFR 164.502(b) and 164.514(d) limits how much protected health information can be sent in the first place.
Read together, those provisions are why the agreement reads the way it does. A business associate agreement is not a formality that shifts the risk downstream. It is the covered entity's own compliance obligation, and the states treated a thin one as a failure by Labcorp rather than only by AMCA. The breach notification duty runs the same direction: the covered entity generally owes notice to affected individuals, which is the mechanism explained in our guide to how HIPAA breach reporting works.
The agreement also borrows definitions from debt collection law. "Debt Collector" tracks the Fair Debt Collection Practices Act definition at 15 U.S.C. 1692a(6), and the debt verification process Labcorp must build references the CFPB's Regulation F at 12 CFR 1006.34.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Divide $2,287,455 by 10.2 million affected Labcorp patients and you get about twenty-two cents a person. Read as a penalty, that number is not a deterrent. It should not be read as a penalty. This settlement is best understood as a compliance decree that happens to carry a modest check, and the interesting question is whether the decree changes behavior at the companies that were not sued.
Two features suggest it might. The debt collector requirements in paragraphs 17 through 22 are unusually specific for a state attorney general settlement. Naming SOC 2 Type 2 and HITRUST, requiring data segmentation in multi-tenant environments, requiring key management hygiene and US-CERT remediation timelines: these are the terms a security team would write, not the terms a lawyer would. Once a document like that is public, it becomes the yardstick other attorneys general use in the next vendor breach, and general counsel at other health systems now have a published list of what regulators consider reasonable. That is how a small settlement does large work.
The other feature is the twelve-month contract amendment deadline. Labcorp has to reopen every existing debt collector contract and add these terms. Debt collectors that serve multiple laboratories will be asked for the same terms by one large client, and it is cheaper to standardize than to maintain two security postures. The obligations flow downhill whether or not the collectors were investigated.
The limits are real too. The obligations sunset after five years. The third-party assessor's report goes to the Connecticut Attorney General under a confidentiality expectation rather than to the public, so nobody outside the coalition will be able to check the work. There is no admission of liability, no finding of fact, and no adjudication of whether Labcorp's original vendor oversight actually violated anything. And the seven non-participating states released nothing, which is a detail worth watching.
The broader pattern is the one to take away. The AMCA breach potentially exposed the data of more than 27.5 million people through a company almost none of them had heard of, because their laboratories and hospitals sent their data there. Vendor risk is now the dominant shape of healthcare data exposure, and enforcement is following it upstream to whoever chose the vendor.
How This Affects You
Start with what this settlement does not do. If your data was in the AMCA breach, this September 2026 settlement pays you nothing. There is no claim form to fill out, no portal, no eligibility questionnaire and no deadline to meet. Any website that offers to file a claim for you against this $2.3 million settlement is not describing a real process. State attorneys general sue on behalf of the state, and the money they recover goes to the state treasury or to consumer protection enforcement funds.
The consumer compensation path is separate, and it runs through a different court. The 23 putative class actions filed against Labcorp over the AMCA Incident were consolidated into a multidistrict litigation in the U.S. District Court for the District of New Jersey, as Labcorp's own quarterly report to the Securities and Exchange Commission records. That filing states that "[o]n March 2, 2026, the parties entered into a Class Action Settlement and Release, which is subject to court approval." Labcorp discloses no settlement amount in that filing, but the attorneys general do. The Connecticut and Delaware releases both state that "Labcorp has agreed to a $35,000,000 settlement in the related class action lawsuit, which is still ongoing with other AMCA client covered entities." The court record supplies what the releases leave out. The deadline to submit a claim in that settlement was September 3, 2026, and on August 20, 2026 the court entered a Final Approval Order and Judgment as to the Labcorp track. Kroll Settlement Administration LLC is the court-appointed administrator, at amcadatabreachsettlement.com. Anyone who filed before the deadline should check there for payment timing. The phrase the attorneys general use, "still ongoing with other AMCA client covered entities," refers to the rest of the multidistrict litigation, which continues against other defendants, not to the Labcorp settlement.
If you were affected and did not file, the practical options now are protective rather than compensatory, and none of them cost money. A credit freeze at each of the three nationwide credit bureaus is free by federal law, stops new accounts from being opened in your name, and can be lifted temporarily when you need credit. Medical identity theft is the specific risk in a breach like this one, so it is worth reading the explanation of benefits statements your insurer sends and questioning any service you did not receive. Our step-by-step walkthrough of what to do after a data breach covers the sequence in more detail.
For settlements that are actually open to claims right now, our class action settlement tracker lists current claim windows and official administrator links. Nothing here is advice about your particular situation, and we cannot tell you whether any specific claim of yours is viable.
Disclaimer: This article is general legal information about a public enforcement settlement, not legal advice, and reading it does not create an attorney-client relationship. Settlement terms, deadlines and court schedules change. Verify anything you plan to act on against the official source documents or consult a licensed attorney in your state.
Related articles
- What to do after a data breach, step by step
- Reporting HIPAA breaches: requirements, timelines and process
- US data privacy laws hub
- Open class action settlement tracker
- State privacy law comparison and tracker
Last updated: 2026-09-25. This is a developing story; details verified as of 2026-09-25.
Frequently Asked Questions
Do I get money from this settlement?
No. The $2,287,455 Labcorp agreed to pay under the September 2026 settlement goes to the 44 participating state attorneys general, not to consumers. There is no claim form, no eligibility check and no individual payout from this settlement. The agreement does not call the payment a penalty; it lets each attorney general apply the state's share to costs of investigation and litigation, attorneys' fees, or a consumer protection enforcement fund. Nothing is distributed to residents.
Is there any settlement that did pay Labcorp patients?
Yes, and it is now closed to new claims. The class actions against Labcorp over the AMCA Incident were consolidated into a multidistrict litigation in the U.S. District Court for the District of New Jersey, In re American Medical Collection Agency, Inc., Customer Data Security Breach Litigation, No. 2:19-md-02904. The Connecticut and Delaware attorneys general both state that Labcorp 'has agreed to a $35,000,000 settlement in the related class action lawsuit, which is still ongoing with other AMCA client covered entities', and Labcorp told the Securities and Exchange Commission that on March 2, 2026 the parties entered into a Class Action Settlement and Release that is subject to court approval. The court record supplies the rest: Labcorp funded a $35,000,000 non-reversionary common fund, the court appointed Kroll Settlement Administration LLC as settlement administrator, the deadline to submit a claim was September 3, 2026, and on August 20, 2026 the court entered a Final Approval Order and Judgment as to the Labcorp track. If you filed before that deadline, contact the administrator about payment timing. If you did not file, the window has closed. The multidistrict litigation continues as to other AMCA client covered entities, whose separate settlement received preliminary approval on August 20, 2026 with a final approval hearing set for January 7, 2027.
Who was affected by the AMCA breach?
According to the Connecticut Attorney General, the intrusion at American Medical Collection Agency potentially exposed the personal information of more than 27.5 million people nationwide across all of AMCA's clients, including 10.2 million Labcorp patients. The settlement agreement describes the incident as occurring at AMCA and being publicly reported in June 2019.
Why was Labcorp held responsible when AMCA was the company that got breached?
Because a covered entity's duty to safeguard patient data does not transfer to its contractor. Under 45 CFR 164.308(b)(1) a HIPAA covered entity may only let a business associate handle electronic protected health information if it obtains documented satisfactory assurances that the information will be safeguarded. The states also invoked each state's consumer protection and breach notification statutes. AMCA itself went through bankruptcy, and the coalition's 2021 settlement with AMCA was suspended because the company could not pay.
Which states are part of this settlement?
Forty-four jurisdictions signed, including the District of Columbia. Connecticut, Florida, Illinois, Indiana, Michigan and Texas served as lead states, with an executive committee of Maryland, Massachusetts, New York, North Carolina and Tennessee. The full signatory list appears in the opening paragraph of the Assurance of Voluntary Compliance.
What is an Assurance of Voluntary Compliance?
It is the instrument state attorneys general use to resolve a consumer protection investigation without filing a lawsuit. The company agrees to specific future conduct and usually a payment, the attorney general releases the claims covered by the investigation, and the agreement remains enforceable by the attorney general. In some states it must be filed with or approved by a court. This one expressly states that it is not an admission of liability.
How long do Labcorp's new security obligations last?
Paragraph 30 provides that the obligations in paragraphs 9 through 22, which include the vendor risk management program and the debt collector contract requirements, expire five years after the October 1, 2026 effective date. Some other provisions, such as the ban on misrepresenting its data protection practices and the independent assessment requirement, are structured separately.
What should I do now if my data was in the AMCA breach?
General protective steps apply to anyone in a breach of this kind. A credit freeze at each of the three nationwide credit bureaus is free under federal law and blocks new accounts opened in your name. Reviewing explanation of benefits statements from your health insurer helps catch medical identity theft. This is general information, not advice about your situation.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Office of the Attorney General, State of Connecticut, “Attorney General Tong Leads Multistate Settlement with Labcorp,” press release, September 24, 2026.(portal.ct.gov).gov
- Assurance of Voluntary Compliance, In the Matter of Laboratory Corporation of America Holdings, entered into by the Attorneys General of 44 jurisdictions, signed September 11 and September 18, 2026, effective October 1, 2026 (25 pp., incl. Appendix A state statute table).(portal.ct.gov).gov
- Delaware Department of Justice, “AG Jennings announces $2.3 million multistate settlement with Labcorp over AMCA Data Breach,” September 24, 2026 (Delaware share $30,135; 115,250 Delaware residents).(news.delaware.gov).gov
- Pennsylvania Office of Attorney General, “Attorney General Sunday Announces Multistate Settlement with Labcorp over American Medical Collection Agency Data Breach,” September 24, 2026 (Pennsylvania share $43,313; approx. 218,408 residents).(attorneygeneral.gov).gov
- 45 C.F.R. § 164.308, Administrative safeguards, paragraph (b), Business associate contracts and other arrangements (U.S. Government Publishing Office, govinfo).(govinfo.gov).gov
- 45 C.F.R. § 164.502, Uses and disclosures of protected health information: General rules, paragraph (e), Disclosures to business associates (U.S. Government Publishing Office, govinfo).(govinfo.gov).gov
- Labcorp Holdings Inc., Form 10-Q for the quarterly period ended June 30, 2026, U.S. Securities and Exchange Commission (discloses the March 2, 2026 Class Action Settlement and Release subject to court approval in the District of New Jersey and the multi-state attorneys general information requests).(sec.gov).gov
- Final Approval Order and Judgment as to the Labcorp track (ECF No. 940), In re American Medical Collection Agency, Inc., Customer Data Security Breach Litigation, No. 2:19-md-02904 (D.N.J. Aug. 20, 2026); Motion for Final Approval (ECF No. 925-1) stating 'The deadline to submit a claim is September 3, 2026' and the non-reversionary $35,000,000 fund; ECF No. 941 granting preliminary approval in the other-labs track with a final approval hearing set for 7 January 2027. Docket via CourtListener/RECAP.(courtlistener.com)