Laboratory Corporation of America (Labcorp) has agreed to a $35 million settlement to resolve litigation related to the American Medical Collection Agency (AMCA) data breach. The settlement addresses claims that millions of patients' protected health information was compromised through Labcorp's business relationship with AMCA, highlighting critical HIPAA compliance obligations for healthcare organizations and their business associates.
Laboratory Corporation of America (Labcorp), one of the nation's largest clinical laboratory companies, has agreed to pay $35 million to settle litigation stemming from the American Medical Collection Agency (AMCA) data breach. This significant settlement underscores the financial and reputational risks healthcare organizations face when third-party vendors experience data security incidents.
The AMCA data breach, which came to light in 2019, affected millions of patients whose personal and medical information was processed by the debt collection agency. AMCA served as a business associate to various healthcare providers, including Labcorp, handling billing and collection services for laboratory testing services.
The breach exposed sensitive patient data including:
This settlement highlights critical HIPAA compliance requirements that healthcare organizations must address when working with business associates:
The Labcorp settlement demonstrates that healthcare organizations cannot simply transfer liability to business associates. Even when third parties cause data breaches, covered entities may still face:
To mitigate risks associated with business associate relationships, healthcare organizations should:
The $35 million Labcorp settlement serves as a stark reminder that healthcare data security extends beyond an organization's direct control. As cyber threats continue to evolve and healthcare data becomes increasingly valuable to criminals, robust business associate management and third-party risk assessment programs are essential components of comprehensive HIPAA compliance strategies.
Labcorp agreed to pay $35 million to settle litigation related to the American Medical Collection Agency (AMCA) data breach that exposed millions of patients' protected health information.
The AMCA breach highlights that healthcare organizations must maintain ongoing oversight of business associates and cannot simply transfer liability. Covered entities remain responsible for ensuring business associates protect patient data appropriately.
The AMCA breach exposed names, addresses, dates of birth, Social Security numbers, medical information, test results, insurance information, and payment card data of millions of patients.
Yes, healthcare organizations can face liability for business associate breaches through patient lawsuits and regulatory action, even when the breach occurs at a third-party vendor, as demonstrated by the Labcorp settlement.
Healthcare organizations should conduct thorough security assessments of business associates, implement ongoing monitoring, strengthen contractual protections, and develop comprehensive third-party risk management programs.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free