Labcorp Settles $2.3 M Over Vendor‑Induced Data Breach Affecting 10 Million Patients
What Happened — A bipartisan coalition of 44 state attorneys general settled a lawsuit against Labcorp for $2.3 million after a 2019 breach exposed the personal health information of 10.2 million customers. The breach originated from security failings at American Medical Collection Agency (AMCA), a debt‑collection vendor Labcorp relied on, ultimately impacting an estimated 27.5 million people nationwide.
Why It Matters for Trust & Control Assurance
- Continuous vendor‑risk monitoring is a core control that prevents third‑party failures from becoming enterprise breaches.
- Documented incident‑response plans for supplier‑related incidents provide the defensible evidence auditors demand.
- Contractual security clauses and regular vendor audits turn “trust” into measurable, auditable assurance.
Who Is Affected
- Health‑care and clinical‑lab organizations (HIPAA‑covered entities).
- Third‑party service providers handling sensitive health data (debt collectors, billing processors).
Recommended Actions
- Map your third‑party risk program to the control objective of vendor oversight and collect contracts, audit reports, and security questionnaires as evidence.
- Develop or update an incident‑response playbook that includes vendor‑specific failure scenarios and test it regularly.
- Enforce contractual security requirements (e.g., mandatory audits, data‑segmentation clauses) for all vendors that process PHI.
Source: The Record
Technical Notes – The breach was not a technical exploit but a supply‑chain failure: AMCA’s inadequate security controls allowed unauthorized access to Labcorp’s patient data. No specific CVE or malware was reported. Source: same as above