A Seven-Year-Old Breach, A New Compliance Regime
On September 24-25, 2026, a bipartisan coalition of 44 state attorneys general — led by Connecticut, Florida, Indiana, Illinois, Michigan, and Texas — announced a $2.3 million settlement with Laboratory Corporation of America (Labcorp) over the 2019 breach at American Medical Collection Agency (AMCA), a billing vendor Labcorp used for debt collection. The breach, which ran from August 2018 to March 2019, exposed personal information — including, in some cases, financial account data — for more than 27.5 million people nationwide, of whom 10.2 million were Labcorp patients (Connecticut AG; Delaware AG).
The fine itself is modest — smaller, per state, than many companies spend on a single quarter of cyber-insurance premiums. What matters is the compliance architecture the settlement imposes. Labcorp must now build a dedicated vendor risk management team, write a vendor-specific incident response plan, cap how much data it hands to debt collectors, embed cybersecurity terms into every vendor contract, require routine vendor audits, retain an independent assessor, and stop letting collectors aggregate data across multiple corporate clients (The Record). New York Attorney General Letitia James framed it plainly: "Millions of patients' private health information was potentially exposed because of Labcorp's failures to protect its customers."
The Case for the Crackdown
The AGs' theory has real force. Labcorp didn't lose the data itself — AMCA did, after leaving a payment portal vulnerable for eight months. But Labcorp chose AMCA, kept sending it patient records, and by the states' account did little to verify AMCA's security posture before or after the breach. AMCA's own liability proved worthless: a court ordered it to pay $21 million in 2021, but the fine was suspended when the company went bankrupt (The Record). If the entity that actually mishandled the data can dissolve and walk away, and the entity that owned the customer relationship faces no durable consequence, outsourcing becomes a liability shield rather than an efficiency tool. Connecticut AG William Tong's framing — "data security is a non-delegable duty" — is the correct legal principle: a company can delegate a task without delegating the accountability for how it's performed.
Where the Mandate Overreaches
But precision matters, and this settlement blurs a distinction that regulation should preserve: the difference between negligent vendor selection and the inherent, irreducible risk of any data-sharing arrangement. Labcorp processes roughly 500,000 lab requisitions a day; every one of its vendors, from collections agencies to cloud storage providers to reference labs, is a potential point of failure that no audit regime eliminates entirely. A prescriptive rule — mandatory third-party assessors, contract inventories, formal data-siloing — imposes real, ongoing compliance costs on every future vendor relationship, and those costs compound most heavily for smaller diagnostic and health-data companies without Labcorp's balance sheet, potentially entrenching incumbents who can absorb the overhead.
The more proportionate question is not whether Labcorp should be held responsible when a chosen vendor is breached, but whether the specific controls now mandated are the ones a well-run compliance program would have adopted anyway — in which case the settlement is a useful public benchmark — or whether they're now baked into consent-decree language that regulators in future cases treat as the floor regardless of a company's actual risk profile or size. Nothing in the public settlement materials suggests the AGs tailored these terms to Labcorp's specific control gaps versus applying a template; that ambiguity is worth resolving before the next 44-state coalition cites this as precedent.
No Federal Backstop, By Design
What's conspicuously absent is any federal regulator. Labcorp's health data sits partly outside HIPAA's reach once it flows to a non-covered debt collector, and the FTC's Health Breach Notification Rule — used against GoodRx in 2023 for a $1.5 million penalty over unauthorized ad-sharing — targets notification failures for non-HIPAA health apps and PHR vendors, not vendor-oversight practices at a HIPAA-covered lab itself (FTC). That gap is exactly why state attorneys general, acting under their own consumer-protection statutes, have become the de facto vendor-security regulator for health data in America — a patchwork that is more responsive than a slow-moving federal rulemaking, but also less predictable, since the next multistate coalition could set a different bar entirely.
The Bottom Line
Holding Labcorp accountable for a vendor it chose and continued to use is defensible; AMCA's bankruptcy proved that letting the breached party alone absorb liability produces no deterrence at all. But durable, proportionate vendor-security policy should come from a rule Congress or the FTC writes once, tested against cost and applied evenly — not from settlement-by-settlement lawyering that risks calcifying into a one-size-fits-all compliance checklist for an industry with wildly different risk profiles.