Labcorp has agreed to a $2.3 million multistate settlement following an investigation into a HIPAA data breach that exposed patient information. The agreement resolves allegations of insufficient security safeguards and requires Labcorp to strengthen its data protection program.
Laboratory Corporation of America Holdings (Labcorp), one of the largest clinical laboratory networks in the United States, has agreed to pay $2.3 million to settle a multistate investigation into a data breach that compromised patient information. The settlement, announced on September 25, 2026, resolves claims brought by a coalition of state attorneys general who alleged that Labcorp failed to implement reasonable safeguards to protect sensitive health data in violation of HIPAA and state consumer protection laws.
The breach at the center of the investigation involved unauthorized access to systems containing protected health information (PHI). While Labcorp has not admitted wrongdoing, the settlement reflects the growing willingness of state regulators to pursue enforcement actions against healthcare organizations that fail to meet baseline security expectations.
Under the terms of the agreement, Labcorp must not only pay the monetary penalty but also implement a comprehensive corrective action plan. This includes:
The breach affected current and former Labcorp patients whose personal and medical information may have been exposed. Affected individuals could include patients who used Labcorp testing services across multiple states, as the multistate investigation spanned jurisdictions across the country.
Exposed data potentially included:
This settlement carries several important compliance lessons for HIPAA-covered entities and business associates:
HIPAA grants state attorneys general authority to bring civil actions on behalf of state residents for violations of HIPAA privacy and security rules. This settlement demonstrates that state-level enforcement is no longer a secondary concern—it is a primary risk vector. Organizations should expect increased scrutiny from state regulators, not just the HHS Office for Civil Rights (OCR).
The monetary penalty is only part of the cost. Labcorp's corrective action plan will require sustained investment in security infrastructure, documentation, and auditing. Organizations should view enforcement actions as multi-year compliance commitments, not one-time fines.
The allegations centered on failure to implement reasonable safeguards—a core HIPAA Security Rule requirement. This reinforces that regulators are examining whether organizations have deployed appropriate technical, administrative, and physical safeguards commensurate with their risk profile.
Healthcare organizations and their business associates should take immediate steps to reduce enforcement risk:
1. Conduct a comprehensive risk assessment — Update your HIPAA Security Risk Analysis to identify gaps in current safeguards.
2. Review access controls — Ensure that only authorized personnel can access PHI and that access is logged and monitored.
3. Strengthen encryption practices — Encrypt PHI both at rest and in transit, and document encryption decisions.
4. Update incident response plans — Test breach response procedures regularly and ensure they comply with HIPAA Breach Notification Rule timelines.
5. Engage state-level compliance monitoring — Track enforcement trends in states where you operate and align policies accordingly.
6. Document everything — Maintain clear records of security measures, risk assessments, and training to demonstrate good-faith compliance efforts.
The Labcorp settlement underscores that data breach enforcement is intensifying, with states playing an increasingly prominent role. Organizations that proactively strengthen their HIPAA compliance programs will be better positioned to avoid similar outcomes.
Labcorp agreed to pay $2.3 million to settle a multistate investigation alleging the company failed to implement reasonable safeguards to protect patient health information, violating HIPAA and state consumer protection laws.
The settlement involved allegations that Labcorp failed to implement adequate technical, administrative, and physical safeguards as required by the HIPAA Security Rule, including insufficient access controls and data protection measures.
A coalition of state attorneys general conducted the multistate investigation, exercising their authority under HIPAA to enforce privacy and security rules on behalf of state residents.
Labcorp must strengthen access controls, enhance encryption of protected health information, conduct regular risk assessments, improve security training, and maintain detailed breach response protocols as part of the settlement.
Organizations should conduct comprehensive risk assessments, implement strong access controls, encrypt PHI at rest and in transit, test incident response plans, and maintain thorough documentation of compliance efforts.
PoliWriter creates all the policies and documentation you need for compliance, customized to your organization. AI-powered, audit-ready, hours not months.
Get Started Free