
New Jersey joins $2.2 million multistate LabCorp settlement over 2019 data breach
TRENTON, N.J. — LabCorp will pay more than $2.2 million and strengthen its data-security practices under a multistate settlement resolving an investigation into a 2019 data breach that potentially exposed personal information belonging to more than 27.5 million people nationwide, including more than 400,000 New Jersey residents, according to the New Jersey Attorney General’s Office.
The breach occurred at Retrieval-Masters Creditors Bureau, doing business as American Medical Collection Agency, a third-party vendor used by LabCorp to collect medical debts. The compromised information included sensitive data belonging to approximately 10.2 million LabCorp patients, including 417,308 in New Jersey.
New Jersey joined 43 other states in reaching the settlement with LabCorp.
“Companies entrusted with consumers’ sensitive health and personal information remain responsible for protecting that information when they share it with outside vendors,” said Attorney General Jennifer Davenport. “Businesses cannot outsource their obligation to safeguard consumer data. This settlement reinforces the importance of carefully vetting vendors and maintaining strong oversight to ensure the information entrusted to them remains secure.”
“Third-party vendors can create significant risks when they are given access to sensitive consumer information without adequate safeguards and oversight,” said Christopher Peterson, Acting Director of the Division of Consumer Affairs. “Companies that collect and maintain consumers’ personal information must have systems in place to assess those risks, monitor their vendors, and act when security deficiencies arise.”
The settlement resolves the states’ investigation into LabCorp’s oversight of American Medical Collection Agency and establishes requirements intended to strengthen the company’s information-security and vendor-management practices.
Under the agreement, LabCorp must strengthen its incident-response plan, minimize the amount of data shared with vendors, expand its vendor-risk management program and impose additional cybersecurity requirements on debt collectors.
The company must also hire an independent third-party assessor to conduct an information-security assessment focused on vendor-risk management.
LabCorp will pay $2,287,455 to the participating states, including $68,000 to New Jersey.
The settlement supplements a 2021 multistate settlement with American Medical Collection Agency that included a suspended $21 million payment because of the company’s bankruptcy. LabCorp also separately agreed to a $35 million settlement in related class-action litigation.
The 2019 breach at American Medical Collection Agency involved an unauthorized user gaining access to its systems and records containing personal, financial and medical information.





