What happened
The New York Attorney General, together with 43 other state AGs, secured a $2.3 million settlement and mandated security reforms from Laboratory Corporation of America (Labcorp) following a 2019 breach that exposed personal and health data of over 27.5 million people. Labcorp must overhaul its information security program, limit data sharing with vendors, and expand vendor risk management, among other obligations.
Penalty
approximately $2.3 million
Why it matters for trust and compliance
- Its status is settled. The case has an outcome that others may cite.
- The settlement forces Labcorp to adopt stronger data‑security and vendor‑risk controls, aiming to protect millions of consumers’ sensitive health information.
- Penalty: approximately $2.3 million.
Who is affected
healthcare financial services controller processor vendor Laboratory Corporation of America (Labcorp) American Medical Collection Agency (AMCA)
Recommended actions
- Revisit retention schedules and data minimisation for the data involved.
- Map the security requirements to existing controls and close gaps.
- Check breach-notification procedures and timelines against the requirement.
- Identify affected vendors and update due-diligence and contract terms.
- Confirm handling of sensitive data categories meets the stricter rules.