Court Rules
All enforcement actions
SettlementHigh RiskMultistate

Multistate Settlement with Labcorp Over AMCA Data Breach

Laboratory Corporation of AmericaSeptember 24, 2026Connecticut Attorney General

Penalty Amount

$2,287,455

Consumers Affected

10,200,000

Summary

Connecticut Attorney General William Tong led a 44-attorney-general coalition settlement with Laboratory Corporation of America over the 2019 AMCA breach, which potentially exposed personal information of more than 27.5 million people, including 10.2 million Labcorp patients. Labcorp will pay $2,287,455 and implement enhanced vendor-risk management, information-security, and oversight measures.

Remedy

Labcorp must pay $2,287,455 to the states, enhance its information security and vendor-risk management programs, minimize data shared with vendors, strengthen debt-collector contract and cybersecurity requirements, and have a third-party assessor conduct an information security assessment focused on vendor risk management.

Monetary PenaltyCompliance ProgramAudit RequirementReporting Requirements

Contract Impact

Review vendor and business associate agreements—especially debt-collection and other vendors handling patient information—for clear security controls, limits on data shared and permitted uses, data segregation, and obligations to report vendor security events promptly. Confirm contracts grant audit and assessment rights, require evidence of ongoing compliance, support incident response and internal escalation, and allow termination for security non-compliance. Review customer-facing privacy notices and employee incident-response procedures for consistency with these vendor oversight commitments.

Contract Search Terms

vendor security assessmentvendor risk managementdata minimizationHIPAA business associate agreementincident response planvendor security incident reportingcybersecurity standards in vendor contractsaudit and assessment rightsdata segregationtermination for security non-compliance

Laws Cited

HIPAA

Violation Types

Entity Details

Entity

Laboratory Corporation of America

Industry

Healthcare

Multistate Coalition

Florida Attorney GeneralIndiana Attorney GeneralIllinois Attorney GeneralMichigan Attorney GeneralTexas Attorney GeneralMaryland Attorney GeneralMassachusetts Attorney GeneralNew York Attorney GeneralNorth Carolina Attorney GeneralTennessee Attorney GeneralAlaska Attorney GeneralAlabama Attorney GeneralArizona Attorney GeneralArkansas Attorney GeneralColorado Attorney GeneralDistrict of ColumbiaDelaware Attorney GeneralGeorgia Attorney GeneralHawaii Attorney GeneralIdaho Attorney GeneralIowa Attorney GeneralKansas Attorney GeneralKentucky Attorney GeneralMaine Attorney GeneralMinnesota Attorney GeneralMissouri Attorney GeneralNebraska Attorney GeneralNevada Attorney GeneralNew Hampshire Attorney GeneralNew Jersey Attorney GeneralNew Mexico Attorney GeneralOhio Attorney GeneralOklahoma Attorney GeneralOregon Attorney GeneralPennsylvania Attorney GeneralRhode Island Attorney GeneralSouth Carolina Attorney GeneralUtah Attorney GeneralVermont Attorney GeneralVirginia Attorney GeneralWashington Attorney GeneralWisconsin Attorney GeneralWest Virginia Attorney General

Official Sources

Source Evidence

Entity Name
"with the Laboratory Corporation of America (“Labcorp”)"
Fine Amount
"Labcorp will make a payment of $2,287,455.00 to the states"
Laws Cited
"HIPAA-covered entities have a duty to protect personal and protected health information"
Violation Types
"The AMCA breach potentially exposed the personal information of over 27.5 million individuals throughout the United States, including 10.2 million Labcorp patients"
Remedy Summary
"Hiring a Third-Party Assessor to perform an information security assessment with a focus on vendor risk management."

Related Enforcement Actions

NY

Laboratory Corporation of America

$2.3M

New York and a bipartisan coalition of 43 other attorneys general reached an agreement with Laboratory Corporation of America (Labcorp) following a 2019 breach at its debt-collection vendor, AMCA, that potentially exposed personal information of more than 27.5 million people. Labcorp will pay $2,287,455 to the states and implement extensive security and vendor-risk reforms.

CO

Laboratory Corporation of America

$2.3M

Colorado and a bipartisan coalition of attorneys general reached a $2,287,455 settlement with Laboratory Corporation of America over the 2019 data breach at its debt collector, American Medical Collection Agency. The settlement requires stronger vendor risk management and information security practices, with particular requirements for medical debt collectors.

CT

National Highway Traffic Safety Administration

Connecticut Attorney General William Tong joined a coalition of states and local governments in filing suit against NHTSA over its rule weakening fuel economy standards for new passenger cars and light trucks. The lawsuit alleges the rule violates the agency’s statutory mandate and the Administrative Procedure Act; no penalty or final remedy is reported.

CT

U.S. Environmental Protection Agency

Connecticut Attorney General William Tong joined a multistate coalition suing the EPA over its repeal of greenhouse gas pollution limits for power plants and separately filed a notice of intent to sue over regulation of existing gas plants. The coalition asks the court to overturn the repeal and restore the protections; the release reports no monetary penalty or final order.

CT

Sandoz Inc. and Fougera Pharmaceuticals Inc.

$400.0M

Connecticut Attorney General William Tong announced a $400 million settlement with Sandoz Inc. and Fougera Pharmaceuticals Inc. resolving allegations that the generic drug manufacturers conspired to inflate prices, limit competition, and restrain trade. The settlement includes consumer restitution and injunctive reforms; court approval was being sought.

CT

U.S. Department of Homeland Security

Connecticut Attorney General William Tong joined a coalition of 21 attorneys general in submitting a comment letter opposing a DHS rule that allows certain affirmative asylum applications to be referred to removal proceedings without an asylum officer interview. The coalition argues the rule violates federal law and harms asylum seekers, including unaccompanied children; this was a policy opposition letter, not a privacy enforcement action.