Attorney General Jeff Jackson Reaches $2.2 Million Settlement with Labcorp Over 2019 Data Breach
Data Breach Compromised More than 500,000 North Carolinians’ Information
FOR IMMEDIATE RELEASE
Thursday, September 24, 2026
Contact: comms@ncdoj.gov
919-538-2809
RALEIGH — Attorney General Jeff Jackson and 44 other attorneys general reached a $2.2 million settlement with Labcorp following a multistate investigation into a 2019 data breach involving Labcorp’s debt collector, the American Medical Collection Agency (AMCA). Labcorp will pay $2,287,455 to the states, including $100,427 to North Carolina.
Data breaches continue to affect people across the state. Last year, businesses and agencies reported 2,349 data breaches, affecting more than 9.2 million North Carolinians. The data breach at AMCA put the personal information of more than 27.5 million people across the country at risk, including 10.2 million Labcorp patients. Of those patients, 508,111 were North Carolinians. While the breach occurred at AMCA, Labcorp was responsible for making sure that its vendors had strong security practices and were protecting sensitive information. The multistate coalition reached a settlement with AMCA in 2021 after the company’s bankruptcy case was dismissed.
“North Carolinians trusted Labcorp with their personal health information, and Labcorp had a responsibility to protect it. That responsibility doesn’t go away when a company works with a third-party vendor,” said Attorney General Jeff Jackson. “This settlement holds Labcorp accountable. Companies must take the security of their customers’ information seriously.”
The settlement creates stronger requirements for protecting patient health information and overseeing vendors that have access to that sensitive information. Specifically, Labcorp is required to:
- Create and implement an information security program with detailed requirements, including an incident response plan.
- Limit the amount of patient information shared with vendors while allowing vendors to meet their legal obligations.
- Expand the vendor risk management program to include a dedicated team to evaluate vendors and verify their compliance.
- Set additional security standards for debt collectors, including keeping track of contracts, requiring cybersecurity protections, separating data from different clients, conducting security reviews, and ending contracts when vendors fail to meet security standards.
- Hiring a Third-Party Assessor to perform an information security assessment with a focus on vendor risk management.
Labcorp also agreed to a separate $35 million settlement in a related class-action lawsuit that is ongoing with other AMCA client covered entities.
Attorney General Jackson is joined in reaching this settlement by the attorneys general of Alaska, Alabama, Arizona, Arkansas, Colorado, Connecticut, the District of Columbia, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New York, New Mexico, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, Wisconsin, and West Virginia.
###
Legal Disclaimer:
EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.