Labcorp agreed to pay $35 million to settle class-action litigation tied to the 2018–2019 cyberattack on its former billing vendor, American Medical Collections Agency, operated by Retrieval-Masters Credit Bureau. Labcorp said the incident affected nearly 10.3 million patients whose personal information had been sent to AMCA and was present in the vendor’s systems between August 2018 and March 2019. Exposed data included Social Security numbers, payment card information, and in some cases medical test names and diagnostic codes.
Under the proposed settlement, eligible class members can seek reimbursement of documented losses of up to $5,000, an estimated pro-rata cash payment of about $50, and two years of medical and healthcare information monitoring. Labcorp denied wrongdoing, and a final fairness hearing is scheduled in New Jersey federal court on Aug. 20. The AMCA breach affected roughly 24 million people across dozens of clients, also hit Quest Diagnostics and BioReference Laboratories, contributed to AMCA’s 2019 bankruptcy, and previously led to a 2021 multistate settlement with 41 state attorneys general.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
A final fairness hearing on the proposed Labcorp settlement is scheduled for Aug. 20 in New Jersey federal court.
Labcorp agreed to pay $35 million to settle class action litigation tied to the AMCA breach affecting nearly 10.3 million patients. The proposed settlement offers reimbursement of documented losses up to $5,000 or an estimated pro-rata cash payment of about $50, plus two years of medical and healthcare information monitoring.
In 2021, a coalition of 41 state attorneys general reached a $21 million settlement with AMCA over the breach. The fines were suspended because of the company's bankruptcy.
The AMCA breach contributed to American Medical Collections Agency's bankruptcy in 2019.
Labcorp said personal information it sent to Retrieval-Masters Credit Bureau, operating as AMCA, was present in AMCA systems during a cyber incident between August 2018 and March 2019. The incident was part of a broader AMCA breach affecting dozens of clients and exposing sensitive data including Social Security numbers and payment card information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
3 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceamcadatabreachsettlement.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.