AGP Picks
View all

Attorney General Sunday Announces Multistate Settlement with Labcorp over American Medical Collection Agency Data Breach

HARRISBURG – Attorney General Dave Sunday announced that Pennsylvania, as part of a coalition of 44 attorneys general, has settled with the Laboratory Corporation of America (Labcorp) resolving a multistate investigation into the 2019 data breach at Labcorp’s debt collector, Retrieval-Masters Creditors Bureau.

The Retrieval-Masters Creditors Bureau, which does business as American Medical Collection Agency (“AMCA”), was responsible for a breach that potentially exposed the personal information of more 27.5 million individuals, nationally, and as many as 218,408 Pennsylvanians. 

The settlement requires Labcorp (and associated debt collectors) to bolster protections, and response and notification plans regarding patient information. Labcorp will pay more than $2.28 million to the states and more than $43,000 to Pennsylvania.

“This settlement will provide necessary protections to minimize the chances of such sensitive medical data being accessed again by bad actors,” Attorney General Sunday said.

While the data breach occurred at AMCA, the data involved was the sensitive data of Labcorp’s patients. While companies can contract with vendors freely and delegate authority, data security is a non-delegable duty. Vendor management remains one of the most challenging areas in cybersecurity, but it is critical that businesses properly vet their vendors and ensure that information shared with those vendors will be kept secure.

Today’s settlement stands for the premise that HIPAA-covered entities have a duty to protect personal and protected health information and oversee vendors entrusted with that information. The settlement provides strong requirements around vendor management, especially medical debt collection including:

  • Developing certain aspects of the company’s information security program, such as an incident response plan that includes internal reporting of vendor security events;
  • Minimizing the sharing of data with vendors while balancing certain needs of debt collectors to meet their legal obligations;
  • Expanding the vendor risk management program to include requiring a dedicated team, employing tools to evaluate vendors, and verifying vendor compliance;
  • Adding specific requirements for debt collectors as a specialized subset of vendors, including maintaining contract inventories, enforcing cybersecurity standards through contract, segmenting data which is often aggregated by debt collectors for multiple clients, and requiring debt collectors to perform assessments and audits, and including the right of termination for non-compliance; and
  • Hiring a Third-Party Assessor to perform an information security assessment with a focus on vendor risk management.

As part of the settlement, Labcorp will make a payment of $ 2,287,455.00 to the states of which $43,313 is payable to Pennsylvania. This settlement will supplement a multistate settlement with AMCA itself which included a $21 million suspended payment due to its bankruptcy. 

Separately, Labcorp has agreed to a $35 million settlement in the related class action lawsuit, which is still ongoing with other AMCA client covered entities. 

###

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Today in Law

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.