A bipartisan coalition of 44 U.S. state attorneys general has settled litigation with Labcorp over alleged cybersecurity and vendor-oversight failures tied to the 2019 breach of debt-collection provider American Medical Collection Agency (AMCA). The incident exposed data relating to 10.2 million Labcorp customers and was part of a broader AMCA compromise affecting 27.5 million people nationwide.
Labcorp will pay $2.3 million and implement extensive data-security reforms. The settlement requires strengthened third-party risk controls, including vendor incident-response planning, cybersecurity provisions in vendor contracts, compliance audits, independent security assessments, reduced data sharing, and segregation of sensitive data.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
A bipartisan coalition of 44 U.S. state attorneys general settled litigation with Labcorp over alleged inadequate oversight of AMCA's data-security practices. Labcorp agreed to pay a $2.3 million fine and implement vendor-security and information-security reforms, including vendor incident-response planning, compliance audits, independent assessments, and data segregation.
A court sided with the coalition of state attorneys general in litigation against AMCA and ordered the company to pay a $21 million fine. The penalty was suspended after AMCA went bankrupt.
A 2019 data breach involving Labcorp's debt-collection vendor, American Medical Collection Agency (AMCA), affected 10.2 million Labcorp customers. The broader AMCA incident affected 27.5 million people nationwide.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.