FOR IMMEDIATE RELEASE
Media Contacts
[email protected]
410-576-7009
BALTIMORE, MD – Attorney General Anthony G. Brown announced that Maryland, as part of a bipartisan coalition of 44 attorneys general, has reached a $2.3 million multistate settlement with the Laboratory Corporation of America (Labcorp) resolving an investigation into the 2019 data breach at Labcorp’s debt collector, Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency (AMCA). The AMCA breach potentially exposed the personal information of over 27.5 million individuals throughout the United States, including 10.2 million Labcorp patients of which 451,558 are Maryland residents. The multistate coalition previously settled with AMCA in 2021.
Although the data breach occurred at AMCA, the sensitive data involved was collected by Labcorp and belonged to Labcorp’s patients. Vendor management remains one of the most challenging areas in cybersecurity, but it is critical that businesses properly vet their vendors and ensure that information shared with those vendors will be kept secure. While companies can contract with vendors freely and delegate authority, they still have a duty to maintain the data they collect securely.
“Marylanders trust healthcare companies to protect their most sensitive medical information, even when that information is shared with outside vendors,” said Attorney General Brown. “This settlement holds Labcorp accountable for failing in that duty and requires the company to maintain stronger vendor oversight to prevent this kind of breach from happening again.”
Today’s settlement stands for the premise that HIPAA-covered entities have a duty to (a) protect personal information and protected health information and (b) oversee vendors entrusted with that data. The settlement provides strong requirements around vendor management, especially medical debt collection, including:
- Expanding the company’s information security program, including its incident response plan to cover vendor security events;
- Minimizing the sharing of data with vendors;
- Requiring a dedicated vendor risk management team that evaluates vendors and verifies vendor compliance;
- Requiring debt collectors to maintain contract inventories, enforce cybersecurity standards through contract, segment data aggregated by debt collectors for multiple clients, and require debt collectors to perform assessments and audits; and
- Hiring a Third-Party Assessor to perform an information security assessment with a focus on vendor risk management.
This settlement will supplement a multistate settlement with AMCA which included a $21,000,000 payment, which was suspended due to its bankruptcy.
The attorneys general of Connecticut, Florida, Indiana, Illinois, Michigan, and Texas led the investigation, assisted by the Executive Committee of the attorneys general of Maryland, Massachusetts, New York, North Carolina, and Tennessee. The attorneys general of Alaska, Alabama, Arizona, Arkansas, Colorado, the District of Columbia, Delaware, Georgia, Hawaiʻi, Idaho, Iowa, Kansas, Kentucky, Maine, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Utah, Vermont, Virginia, Washington, Wisconsin, and West Virginia joined the investigation.
###