Office of the Attorney General of Illinois

09/24/2026 | Press release | Distributed by Public on 09/24/2026 15:02

ATTORNEY GENERAL RAOUL ANNOUNCES MULTISTATE SETTLEMENT WITH LABCORP OVER AMERICAN MEDICAL COLLECTION AGENCY DATA BREACH

ATTORNEY GENERAL RAOUL ANNOUNCES MULTISTATE SETTLEMENT WITH LABCORP OVER AMERICAN MEDICAL COLLECTION AGENCY DATA BREACH

September 24, 2026

Chicago - Attorney General Kwame Raoul, as part of a bipartisan coalition of 44 state attorneys general, has secured a settlement with the Laboratory Corporation of America (Labcorp) resolving a multistate investigation into the 2019 data breach at Labcorp's debt collector, Retrieval-Masters Creditors Bureau, doing business as American Medical Collection Agency (AMCA). The AMCA breach potentially exposed the personal information of over 27.5 million individuals throughout the United States, including 10.2 million Labcorp patients, over 175,000 of whom are Illinois residents. The multistate coalition settled with AMCA in 2021.

"Companies can contract with vendors freely and delegate authority, but data security is a non-delegable duty," Raoul said. "It is critical that businesses properly vet their vendors and make sure that sensitive information shared with those vendors is kept secure. Today's settlement ensures that Labcorp will take steps to protect against a future data breach and better protect consumers."

While the data breach occurred at AMCA, the data involved was the sensitive data of Labcorp's patients. Today's settlement stands for the premise that HIPAA-covered entities have a duty to protect personal and protected health information and oversee vendors entrusted with that information.

Raoul's office played an integral role in obtaining the settlement, which includes important injunctive relief to protect consumers' data. The settlement provides strong requirements around vendor management, especially medical debt collection including:

  • Developing certain aspects of the company's information security program, such as an incident response plan that includes internal reporting of vendor security events.
  • Minimizing the sharing of data with vendors, while balancing certain needs of debt collectors to meet their legal obligations.
  • Expanding the vendor risk management program to include requiring a dedicated team, employing tools to evaluate vendors and verifying vendor compliance.
  • Adding specific requirements for debt collectors as a specialized subset of vendors, including maintaining contract inventories; enforcing cybersecurity standards through contract; segmenting data, which is often aggregated by debt collectors for multiple clients; and requiring debt collectors to perform assessments and audits, and including the right of termination for non-compliance.
  • Hiring a third-party assessor to perform an information security assessment with a focus on vendor risk management.

As part of the settlement, Labcorp will make a payment of nearly $2.3 million to the states, $98,126 of which will go to Illinois. This settlement will supplement a multistate settlement with AMCA that included a $21 million suspended payment due to the company's bankruptcy. Separately, Labcorp has agreed to a $35 million settlement in the related class action lawsuit, which is still ongoing with other AMCA client covered entities.

Attorney General Raoul and the attorneys general of Connecticut, Florida, Indiana, Michigan and Texas led the investigation, assisted by the executive committee comprised of the attorneys general of Maryland, Massachusetts, New York, North Carolina and Tennessee. Also joining the settlement are the attorneys general of Alaska, Alabama, Arizona, Arkansas, Colorado, the District of Columbia, Delaware, Georgia, Hawaii, Idaho, Iowa, Kansas, Kentucky, Maine, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Utah, Vermont, Virginia, Washington, Wisconsin and West Virginia.

Office of the Attorney General of Illinois published this content on September 24, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 24, 2026 at 21:02 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]