Pennsylvania Joins Multistate Settlement Over Labcorp Data Breach

Pennsylvania will receive over $43,000 as part of a $2.28 million multistate settlement with Labcorp over a 2019 data breach that exposed personal information of millions. The breach occurred at a third-party debt collector, and the settlement requires Labcorp to strengthen vendor management and security. The agreement also includes hiring a third-party assessor for information security.
The settlement stems from a 2019 breach at Retrieval-Masters Creditors Bureau, a third-party collector for Labcorp, which exposed data for 27.5 million patients nationally, including over 218,000 in Pennsylvania. The $2.28 million payout is separate from a prior $21 million AMCA settlement suspended due to bankruptcy, and a $35 million class-action settlement involving other AMCA clients.
Under the agreement, Labcorp must adopt stricter vendor oversight, improve breach response protocols, and undergo independent security assessments focused on third-party risk. This case underscores that companies cannot outsource liability for data protection, even when vendors hold the compromised information.
This settlement could reinforce accountability for healthcare firms using outside vendors, signaling that patient data security is a shared legal duty. Affected individuals may gain modest financial relief, but the broader impact lies in pressuring organizations to audit third-party practices more rigorously. If widely applied, such agreements may deter lax vendor management, though they cannot fully prevent future breaches or restore privacy once compromised.