In June, LabCorp settled a class action lawsuit over the 2018 American Medical Collection Agency (AMCA) breach for $35 million. Now it has settled charges by state attorneys general stemming from the same incident. Bank Info Security reports:
LabCorp has agreed to pay $2.2 million and improve its data security and vendor risk management practices – especially with debt collectors – to resolve multistate litigation stemming from a 2019 hack on American Medical Collections Agency.
The hack affected more than 10.2 million patients of the medical testing lab, and the settlement announced on Thursday resolves a list of claims against North Carolina-based LabCorp involving a variety of state consumer protection and personal information protection laws, as well violations of federal laws, including HIPAA. Under the HITECH Act of 2009, state attorneys general were granted the right to pursue federal HIPAA violations.
Retrieval-Masters Creditors Bureau, a then-42-year-old New York business operating under the name American Medical Collection Agency, or AMCA, filed for bankruptcy just weeks after discovering the breach in 2019 and ultimately went out of business.
Besides LabCorp, the AMCA hack affected dozens of the firm’s other clients and about 27.5 million people nationwide.
Read more at Bank Info Security.
