Pennsylvania has joined a 44-state settlement with Laboratory Corporation of America over a 2019 data breach at a medical debt collector that handled information belonging to Labcorp patients.
The Pennsylvania Attorney General’s Office says the breach at Retrieval-Masters Creditors Bureau, which did business as American Medical Collection Agency, may have exposed information connected to more than 27.5 million people nationwide and as many as 218,408 Pennsylvanians.
Under the settlement, Labcorp will pay more than $2.28 million to the participating states, including $43,313 to Pennsylvania. The company and associated debt collectors must also strengthen protections for patient information and improve their response and notification plans.
The requirements include a more developed incident-response program, limits on data shared with vendors, a dedicated vendor-risk team, compliance checks and more specific cybersecurity obligations for debt collectors. Labcorp must also hire an independent assessor to review its information-security program with a focus on vendor risk.
The Attorney General’s Office says health-care organizations remain responsible for protecting patient data even when outside vendors handle billing or collections. The new agreement supplements an earlier settlement with the debt collector itself, whose $21 million payment was suspended because of bankruptcy.
A separate $35 million proposed class-action settlement involving Labcorp remains pending alongside claims involving other organizations whose data was handled by the collection company.













