What happened

A bipartisan coalition of 44 state attorneys general announced on Thursday that it had settled its lawsuit against Laboratory Corporation of America. Labcorp will pay a $2.3 million fine and carry out sweeping changes to how it manages data security, following a 2019 breach that affected 10.2 million of its customers.

The breach began with security failings at American Medical Collection Agency, a debt collector that Labcorp used. The same incident affected 27.5 million people nationwide. The attorneys general argued that Labcorp should have done more to police the vendor, given the volume of patient medical data it handed over.

The required reforms are specific. Labcorp must create an incident response plan for vendor security failings, limit how much data it shares with vendors, and build a wider risk management team responsible for tracking vendors' compliance with data security practices. New vendor contracts must include cybersecurity requirements, and data collectors must routinely provide the company with audits documenting their compliance. Labcorp will also retain an independent expert to conduct information security assessments, and it must begin separating or siloing data that debt collectors aggregate across several clients at once.

New York Attorney General Letitia James said millions of patients' private health information was potentially exposed because of Labcorp's failure to protect its customers, and that the settlement would force changes to prevent a repeat. AMCA itself was ordered to pay a $21 million fine in 2021, which was suspended when the company went bankrupt. Labcorp did not issue a press release about the settlement and did not immediately respond to a request for comment.

Why this is a GRC story

Using a vendor does not transfer the duty to oversee it. That is the whole theory of the case, and it is why the remedy is written into contracts. Security requirements, routine audits and limits on data sharing are the mechanisms a regulator will look for when the next vendor fails.

Audit rights only count when they are used. The settlement requires collectors to supply compliance audits on a routine schedule, which turns a clause sitting in a contract into an operating obligation with a paper trail.

Siloing is a blast radius control. Debt collectors aggregate records across many clients, so one compromise exposes everyone at once. Separating that data limits how far a single failure travels, and it is the kind of control worth designing before a vendor is onboarded rather than after.

Independent assessment adds teeth. Retaining an external expert to test information security is the pattern regulators use when they want verifiable assurance rather than self-reporting.

What to watch

Watch whether other state attorneys general reuse this template in vendor-linked breach cases, since the package, rather than the fine, is the part that changes behaviour. Watch also how health data collectors respond as contracts with security and audit terms become the price of doing business with large providers.

The practical takeaway: the fine is small against the exposure. Pull your vendor list, confirm which ones hold regulated data, check whether contracts carry security terms and audit rights, and then confirm somebody is actually exercising those rights on a schedule.

Attribution: Analysis based on The Record and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News