Home › Intelligence › Brief
BREACH BRIEF 🟠 High Breach

Labcorp Settles $2.3 M Over Vendor‑Induced Data Breach Affecting 10 Million Patients

A coalition of state attorneys general fined Labcorp $2.3 million after a 2019 breach tied to its debt‑collection vendor exposed 10.2 million patients’ health data. The settlement underscores the need for robust third‑party risk controls and auditable vendor contracts.

Verisq™ Intelligence · 📅 September 26, 2026 · 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
2 recommended
📰
Source
therecord.media

Labcorp Settles $2.3 M Over Vendor‑Induced Data Breach Affecting 10 Million Patients

What Happened — A bipartisan coalition of 44 state attorneys general settled a lawsuit against Labcorp for $2.3 million after a 2019 breach exposed the personal health information of 10.2 million customers. The breach originated from security failings at American Medical Collection Agency (AMCA), a debt‑collection vendor Labcorp relied on, ultimately impacting an estimated 27.5 million people nationwide.

Why It Matters for Trust & Control Assurance

  • Continuous vendor‑risk monitoring is a core control that prevents third‑party failures from becoming enterprise breaches.
  • Documented incident‑response plans for supplier‑related incidents provide the defensible evidence auditors demand.
  • Contractual security clauses and regular vendor audits turn “trust” into measurable, auditable assurance.

Who Is Affected

  • Health‑care and clinical‑lab organizations (HIPAA‑covered entities).
  • Third‑party service providers handling sensitive health data (debt collectors, billing processors).

Recommended Actions

  • Map your third‑party risk program to the control objective of vendor oversight and collect contracts, audit reports, and security questionnaires as evidence.
  • Develop or update an incident‑response playbook that includes vendor‑specific failure scenarios and test it regularly.
  • Enforce contractual security requirements (e.g., mandatory audits, data‑segmentation clauses) for all vendors that process PHI.

Source: The Record

Technical Notes – The breach was not a technical exploit but a supply‑chain failure: AMCA’s inadequate security controls allowed unauthorized access to Labcorp’s patient data. No specific CVE or malware was reported. Source: same as above

📰 Original Source
https://therecord.media/labcorp-to-overhaul-security-practices-settlement ↗

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →