AG Jennings announces $2.3 million multistate settlement with Labcorp over AMCA Data Breach

Attorney General Kathy Jennings today announced that Delaware, as part of a coalition of 44 attorneys general, has reached a $2.3 million multistate settlement with the Laboratory Corporation of America (“Labcorp”) resolving the multistate investigation into the 2019 data breach at Labcorp’s debt collector, Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency (“AMCA”). The AMCA breach potentially exposed the personal information of over 27.5 million individuals throughout the United States, including 10.2 million Labcorp patients of which 115,250 are Delaware residents. The multistate coalition settled with AMCA in 2021 after the company’s bankruptcy petition was dismissed.

While the data breach occurred at AMCA, the data involved was the sensitive data of Labcorp’s patients. While companies can contract with vendors freely and delegate authority, data security is a non-delegable duty. Vendor management remains one of the most challenging areas in cybersecurity, but it is critical that businesses properly vet their vendors and ensure that information shared with those vendors will be kept secure.

“Companies rely on vendors of all kinds to help them do business. But the responsibility to manage and protect consumers’ sensitive personal information cannot be outsourced,” said AG Jennings. “My office will continue to hold companies accountable when they fail to adequately safeguard consumer data, including when they fail to properly oversee their vendors.”

Today’s settlement stands for the premise that HIPAA-covered entities have a duty to protect personal and protected health information and oversee vendors entrusted with that information. The settlement provides strong requirements around vendor management, especially medical debt collection including:

  • Developing certain aspects of the company’s information security program, such as an incident response plan that includes internal reporting of vendor security events;
  • Minimizing the sharing of data with vendors while balancing certain needs of debt collectors to meet their legal obligations;
  • Expanding the vendor risk management program to include requiring a dedicated team, employing tools to evaluate vendors, and verifying vendor compliance;
  • Adding specific requirements for debt collectors as a specialized subset of vendors, including maintaining contract inventories, enforcing cybersecurity standards through contract, segmenting data which is often aggregated by debt collectors for multiple clients, and requiring debt collectors to perform assessments and audits, and including the right of termination for non-compliance; and
  • Hiring a Third-Party Assessor to perform an information security assessment with a focus on vendor risk management.

As part of the settlement, Labcorp will make a payment of $ 2,287,455 to the states of which $30,135 is payable to Delaware. This settlement will supplement a multistate settlement with AMCA itself which included a $21,000,000 suspended payment due to its bankruptcy. Separately Labcorp has agreed to a $35,000,000 settlement in the related class action lawsuit, which is still ongoing with other AMCA client covered entities.