A coalition of 44 state attorneys general has reached an approximately $2.3 million settlement with Labcorp over a 2019 data breach at a medical debt collector that handled Labcorp patient information. The agreement focuses on how the laboratory company oversees vendors holding sensitive patient data; the state announcement does not describe this $2.3 million as a consumer refund fund.
Delaware Attorney General Kathy Jennings announced the settlement September 24. The debt collector was Retrieval-Masters Creditors Bureau, doing business as American Medical Collection Agency, or AMCA. The breach potentially exposed information about more than 27.5 million people nationwide, including 10.2 million Labcorp patients, according to the Delaware announcement. "Potentially exposed" does not mean every person's data was misused.
Under the agreement described by Delaware, Labcorp will strengthen its vendor risk program, maintain an incident-response process for vendor security events, limit sharing of data where appropriate, and impose additional security standards and assessment requirements on debt-collection vendors. A third-party assessor will review its information-security program with a focus on vendor risk management. Labcorp's payment to the states is $2,287,455, including $30,135 to Delaware.
The state distinguishes this multistate agreement from a separate $35 million class-action settlement related to the breach. Consumers should not confuse the two or infer a personal payment from the states' agreement. The Delaware announcement does not set out a claims process for individuals under this state settlement.
Medical bills can reach a collector even when the original provider's name is more familiar to the patient. Anyone contacted about an old medical balance can ask for written details and check the debt independently before providing financial information. Financialist's state debt guides cover general collection rules by location; they do not determine whether someone was affected by this breach.