Local

Pennsylvania part of multistate settlement with Labcorp following 2019 data breach

Pennsylvania part of multistate settlement with Labcorp following 2019 data breach

Pennsylvania Attorney General Dave Sunday announced a multistate settlement with Laboratory Corporation of America following a major 2019 data breach at the company’s former debt collector.

The agreement resolves an investigation by a coalition of 44 attorneys general into a security compromise that exposed the personal information of more than 27.5 million people nationwide.

The breach occurred at Retrieval-Masters Creditors Bureau, doing business as American Medical Collection Agency, an outside vendor contracted by Labcorp to handle debt collection.

While the security incident originated at the third-party collector, the compromised records contained sensitive patient health data from Labcorp, including information belonging to 218,408 Pennsylvanians.

Under the terms of the multistate agreement, Labcorp will pay $2,287,455 to the participating states, with $43,313 allocated to Pennsylvania. The payout supplements an earlier multistate settlement reached directly with AMCA, which included a $21 million payment that was suspended due to the debt collector’s bankruptcy filing.

The agreement establishes cybersecurity obligations for entities covered by the Health Insurance Portability and Accountability Act. Although health care companies routinely hire external vendors, state officials noted that data security remains a primary responsibility that cannot be delegated.

“This settlement will provide necessary protections to minimize the chances of such sensitive medical data being accessed again by bad actors,” Sunday said.

The settlement mandates specific updates to Labcorp’s vendor risk management and information security programs. Labcorp must create an incident response plan to handle internal reporting of vendor security events, limit patient data shared with debt collection agencies and employ dedicated staff and tools to evaluate vendor compliance.

Specialized requirements for debt collectors include maintaining contract inventories, enforcing contractual cybersecurity standards, segmenting customer data, conducting security audits and establishing contract termination rights for non-compliance.

Labcorp is also required to hire a third-party assessor to evaluate its information security and vendor risk protocols.

In addition to the state regulatory agreement, Labcorp agreed to a separate $35 million settlement in a related class action lawsuit. That litigation remains ongoing against other health care entities that contracted with AMCA.

Download the FREE WPXI News app for breaking news alerts.

Follow Channel 11 News on Facebook and Twitter. | Watch WPXI NOW

0