Labcorp settles $2.3B data breach lawsuit brought by 44 states
The fallout from a 2019 hack that exposed 27.5 million patient records is finally wrapping up, as 44 state attorneys general have come to a settlement agreement with diagnostics company Labcorp, one of the largest sources of data stemming from the breach on a medical debt collections company.
That company, American Medical Collection Agency (AMCA), is a subsidiary of an even larger debt collector called Retrieval-Masters Creditors Bureau. When its network was breached in March 2019, records from Labcorp accounted for 10.5 million of those exposed to cybercriminals.
To resolve a lawsuit in which a coalition of plaintiffs representing state governments sought to hold Labcorp partially responsible for the incident because it trusted AMCA with its data, the company opted to pay a settlement of nearly $2.3 billion, to be divided among the states.
In addition, Labcorp, a publicly traded business based in North Carolina, has also agreed to change the way it allows vendors to access and store its sensitive patient data, for all purposes including debt collections.
The new requirements Labcorp agreed to include:
- The development of an incident response plan that determines how the company will respond to cybersecurity incidents at its vendors, to include ways to ensure data is secured as quickly as possible.
- Data sharing will also be limited, meaning records can and should only contain the information third parties need to do their work—in this case, debt collections.
- Regular compliance checks with vendors that assess risk of patient information being exposed.
- Adding additional cybersecurity requirements for vendors, with a particular emphasis on debt collectors, to include demands that data be segregated and secured properly.
- An agreement to hire a third-party cybersecurity firm to develop ongoing protocols aimed at improving data privacy.
Despite the concessions and the settlement payout, Labcorp does not have to admit to any wrongdoing, and has not been found to be liable for the lax security at AMCA.
Largest breach of the year
The cyber-intrusion on AMCA was the largest reported to the federal government related to healthcare in 2019, but it’s also notable for other reasons. For starters, the unauthorized individual or group was inside the network of the debt collection agency for nearly 8 months, from Aug. 1, 2018, to March 30, 2019.
The scope of exposed information was also excessive, going beyond simple unpaid medical bills. Potentially exfiltrated data included patient names, contact information, Social Security numbers, financial records, medical testing details—and diagnostic codes used for billing, that effectively exposed the test results and other details on the health of patients.
The incident has resulted in multiple class action lawsuits against AMCA, where Labcorp is also named as a defendant in some cases.
With this settlement, however, the case brought by state attorneys general is officially resolved. States will receive a portion of the nearly $2.3 billion arrangement based on the number of residents in their states who have been identified as victims.
HealthExec reached out to Labcorp for comment.
