Labcorp has agreed to pay $2.3 million and implement sweeping data security reforms as part of a settlement with a bipartisan coalition of 44 state attorneys general. The settlement resolves a lawsuit over a 2019 data breach that impacted 10.2 million Labcorp customers, with the breach originating at American Medical Collection Agency (AMCA), a debt collector vendor Labcorp worked with.

The attorneys general argued that Labcorp should have done more to police AMCA, whose broader incident affected 27.5 million people nationwide. Under the settlement, Labcorp must create an incident response plan for vendor security failures, limit the data it shares with vendors, and build a risk management team to track vendor compliance with data security practices.

Labcorp must also include cybersecurity requirements in vendor contracts, require routine compliance audits from data collectors, retain an independent expert for information security assessments, and silo data that debt collectors often aggregate across clients. The source notes that Labcorp did not immediately respond to a request for comment and did not issue a press release about the settlement.