Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
Labcorp will pay $2.3 million and overhaul vendor security after a 2019 breach of 10.2 million customers.
A bipartisan coalition of 44 state attorneys general settled with Labcorp for a $2.3 million fine and mandated data-security reforms tied to a 2019 breach. The incident originated at debt collector American Medical Collection Agency and affected 10.2 million Labcorp customers, part of 27.5 million people impacted nationwide. Required changes include vendor incident-response planning, limits on data shared with vendors, contractual cybersecurity requirements, routine vendor audits, an independent security assessment, and data siloing. In 2021 a court ordered bankrupt AMCA to pay a suspended $21 million fine.
- Forty-four state attorneys general settled with Labcorp for $2.3 million.
- The 2019 breach via AMCA exposed data on 10.2 million Labcorp customers.
- The AMCA incident affected 27.5 million people nationwide; a $21 million AMCA fine was suspended after bankruptcy.
- Labcorp must tighten vendor contracts, limit data sharing, and add incident response and independent assessments.
Full article289 words · extracted from therecord.media · click to collapse
A bipartisan coalition of 44 state attorneys general on Thursday announced that they settled a lawsuit against Labcorp in exchange for a $2.3 million fine and a promise of sweeping data security reforms in the wake of a 2019 data breach that impacted 10.2 million customers. The data breach originated with security failings at American Medical Collection Agency (AMCA), a debt collector that Labcorp worked with. The attorneys general contended that Labcorp should have don’t more to police AMCA, after the incident there impacted a total of 27.5 million people nationwide. Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices. Labcorp must also include cybersecurity requirements in vendor contracts and mandate that data collectors routinely provide the medical testing giant with audits documenting their compliance with the new rules. It must also retain an independent expert to conduct information security assessments and begin siloing data that debt collectors often aggregate for several clients at once. In 2021, a court sided with the coalition of attorneys general suing AMCA and ordered the debt collector pay a $21 million fine that was suspended because the company went bankrupt. “Millions of patients’ private health information was potentially exposed because of Labcorp’s failures to protect its customers,” New York Attorney General Letitia James said in a statement Thursday. “As a result of our investigation, Labcorp will make critical changes to protect patients and prevent this kind of data breach from happening again.” A Labcorp spokesperson did not immediately respond to a request for comment and the company did not issue a press release about the settlement.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/labcorp-to-overhaul-security-practices-settlement