Your Vendor’s Breach Can Become Your Lawsuit: The Labcorp Settlement
Last week, Laboratory Corporation of America Holdings (Labcorp) agreed to pay $2,287,455 to a coalition of 44 state attorneys general and to overhaul the way it manages third-party vendors. The settlement, announced September 24-25, 2026 and led by New York Attorney General Letitia James, closes out a multistate investigation into a data breach that did not even happen on Labcorp's own systems.
The breach belonged to Labcorp's debt-collection vendor, the American Medical Collection Agency (AMCA). An intruder had unauthorized access to AMCA's payment portal and back-end systems from August 2018 through March 2019, nearly eight months, before the breach was detected. Because AMCA pooled billing and collections data from its many clients in shared systems, the compromise cascaded far beyond one company: about 27.5 million people were affected across AMCA's client roster, including 10.2 million Labcorp patients. The exposed information included names, Social Security numbers, financial account data, and medical test results and diagnostic codes. It was the largest healthcare-sector data breach reported under HIPAA in 2019.
Why regulators went after the customer, not just the vendor
AMCA is largely gone. It filed for bankruptcy under the weight of remediation costs, and a $21 million multistate judgment against it in 2021 was suspended because the company could not pay. That left state attorneys general looking upstream at the healthcare companies that had entrusted AMCA with patient data in the first place.
The legal theory, echoed by Connecticut Attorney General William Tong, is that data security is a non-delegable duty. When you hand sensitive personal information to a vendor, you do not hand off the legal responsibility to protect it. The vendor may cause the breach, but the company that collected the data and chose the vendor can still face enforcement, class actions, and reputation damage. Labcorp separately agreed to a $35 million settlement in a related federal class-action lawsuit.
Why this matters beyond healthcare
You do not have to be a hospital or a laboratory to take the lesson. Any business that shares customer data with outside companies faces the same exposure. Payroll processors, cloud providers, billing vendors, marketing analytics firms, collection agencies: if they hold your customers' information and get breached, your customers will name you in the lawsuit and regulators will ask why you trusted that vendor with that data.
Two facts from the AMCA episode make the point. First, banks processing AMCA's payments had flagged suspicious activity during the intrusion window, but AMCA failed to identify or contain it. Your vendors' early warning systems only help if someone is watching. Second, the scale of the breach was a direct result of AMCA aggregating many clients' data in shared systems. Data you share can travel into architectures you never reviewed.
Two practical takeaways
Know what your vendors hold, and put security in the contract.
Build security requirements directly into every vendor agreement, not just a generic data processing addendum. That means audit rights, defined breach notification timelines, the right to terminate on security failures, and clauses requiring your data to be segmented from other clients' data. Before you sign, do real diligence on the vendor's security posture, and repeat it on a schedule rather than treating onboarding as a one-time check.
Share less and watch more.
Limit what you send vendors to the minimum they need to do the job, and consider whether a function like debt collection really requires diagnostic codes or full Social Security numbers. Establish a standing vendor risk management process with continuous monitoring, and build an incident response plan specifically for vendor-originated failures, including who gets notified, when, and who makes the call. When a breach is someone else's fault, your customers will not care. The settlement makes clear that regulators will not either.
Gabriel Vincent Tese is an attorney with Spector Gadon Rosen Vinci P.C. in Philadelphia focused on cyber litigation and technology law. He can be reached at gtese@sgrvlaw.com.
This post is general information, not legal advice. For advice about your specific situation, consult an attorney.

