# State Attorneys General Settle Labcorp Data Breach

State Attorneys General from Delaware, Pennsylvania, North Carolina, and a coalition of 45 states announced a multistate settlement with Laboratory Corporation of America (Labcorp) totaling approximately **$2.3 million** to resolve investigations into the 2019 data breach involving its third-party debt collection vendor, American Medical Collection Agency (AMCA). The breach compromised sensitive personal and medical information of over 27.5 million individuals nationwide. The settlement mandates Labcorp to implement enhanced data security measures and stringent vendor management practices to better protect patient information and reduce risks associated with third-party vendors.

- **Why this matters:** Procurement professionals managing contracts with healthcare vendors must prioritize rigorous vendor oversight and cybersecurity requirements to mitigate data breach risks.
- The settlement highlights the increasing regulatory scrutiny on HIPAA-covered entities and their third-party service providers, emphasizing contractual obligations for data protection.
- Organizations should evaluate and strengthen vendor risk management frameworks, including security audits and compliance monitoring, especially for vendors handling sensitive health data.
- This development signals potential for increased contractual provisions and compliance mandates in healthcare-related procurements involving data handling and debt collection services.

**Jurisdictions:** sled
**Industries:** Healthcare
**Topics:** Cybersecurity
**Published:** September 24, 2026

### Government Entities
- State of Delaware
- Pennsylvania Office of Attorney General
- North Carolina Department of Justice (NCDOJ)
- Office of the Attorney General of Alaska
- Office of the Attorney General of Alabama

### Vendors
- Laboratory Corporation of America (settling party)
- Labcorp (settlement party)
- American Medical Collection Agency (AMCA) (third-party vendor involved in breach)

### Key Quotes
> North Carolinians trusted Labcorp with their personal health information, and Labcorp had a responsibility to protect it. That responsibility doesn’t go away when a company works with a third-party vendor.
> — Jeff Jackson, Attorney General

> Companies rely on vendors of all kinds to help them do business. But the responsibility to manage and protect consumers’ sensitive personal information cannot be outsourced.
> — Kathy Jennings, Attorney General

> This settlement will provide necessary protections to minimize the chances of such sensitive medical data being accessed again by bad actors.
> — Dave Sunday, Attorney General

### Sources
- [AG Jennings announces $2.3 million multistate settlement with Labcorp over AMCA Data Breach - State of Delaware News](https://news.delaware.gov/2026/09/24/ag-jennings-announces-2-3-million-multistate-settlement-with-labcorp-over-amca-data-breach/) - DE
- [Attorney General Sunday Announces Multistate Settlement with Labcorp over American Medical Collection Agency Data Breach - PA Office of Attorney General](https://www.attorneygeneral.gov/taking-action/attorney-general-sunday-announces-multistate-settlement-with-labcorp-over-american-medical-collection-agency-data-breach/) - Attorney General
- [Attorney General Jeff Jackson Reaches $2.2 Million Settlement with Labcorp Over 2019 Data Breach - NCDOJ](https://ncdoj.gov/attorney-general-jeff-jackson-reaches-2-2-million-settlement-with-labcorp-over-2019-data-breach/) - Ncdoj