The data breach originated with security failings at American Medical Collection Agency (AMCA), a debt collector that Labcorp worked with.
The attorneys general contended that Labcorp should have don’t more to police AMCA, after the incident there impacted a total of 27.5 million people nationwide.
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
In 2021, a court sided with the coalition of attorneys general suing AMCA and ordered the debt collector pay a $21 million fine that was suspended because the company went bankrupt.
“As a result of our investigation, Labcorp will make critical changes to protect patients and prevent this kind of data breach from happening again.”