Court Rules
All enforcement actions
SettlementHigh RiskMultistate

LabCorp Multistate Settlement Over 2019 Vendor Data Breach

Laboratory Corporation of America Holdings (LabCorp)September 24, 2026New Jersey Attorney General

Penalty Amount

$2,287,455

Consumers Affected

10,200,000

Summary

Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.

Remedy

LabCorp must pay $2,287,455 to participating states and strengthen its information-security and vendor-risk management programs. Requirements include minimizing data shared with vendors, expanding vendor assessments and verification, imposing cybersecurity and audit obligations on debt collectors through contracts, planning for vendor security incidents, and hiring an independent assessor to evaluate vendor-risk management.

Monetary PenaltyCompliance ProgramAudit Requirement

Contract Impact

Review vendor and business associate agreements, especially those with debt collectors and other service providers handling patient or other sensitive information. Confirm data-processing clauses limit shared data to what is necessary; require security controls, data segmentation, risk assessments, audits, and documented compliance verification; and mandate prompt reporting of vendor security events to support internal incident response. Add clear remediation and termination rights for security failures, and ensure customer-facing privacy notices and related agreements accurately describe vendor data sharing and safeguards.

Contract Search Terms

vendor information-security requirementsvendor risk assessment and monitoringdata minimization and sharing limitsincident-response and vendor-event reportingcybersecurity standards in vendor contractsvendor audit and compliance verification rightsdata segmentation requirementsvendor termination for security noncomplianceindependent security assessment

Laws Cited

Health Insurance Portability and Accountability Act (HIPAA)

Violation Types

Entity Details

Entity

Laboratory Corporation of America Holdings (LabCorp)

Industry

Healthcare

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"LabCorp will pay $2,287,455 to the participating states"
Fine Amount
"LabCorp will pay $2,287,455 to the participating states, including $68,000 to New Jersey."
Laws Cited
"entities covered by the Health Insurance Portability and Accountability Act"
Violation Types
"The breach occurred at Retrieval-Masters Creditors Bureau, doing business as American Medical Collection Agency (AMCA), a third-party vendor LabCorp used to collect medical debts."
Violation Types
"The compromised information included sensitive data belonging to approximately 10.2 million LabCorp patients, including 417,308 in New Jersey."

Related Enforcement Actions

NJ

Credit Acceptance Corporation (CAC)

$694.0M

New Jersey's Attorney General and Division of Consumer Affairs, along with 41 Attorneys General, reached a $694 million settlement with subprime auto lender Credit Acceptance Corporation over allegations it originated unaffordable loans its own systems predicted borrowers could not repay, employed aggressive debt-collection tactics, and failed to prevent deceptive vehicle-service contract and GAP product 'packing' by dealers. The multistate settlement stepped in after the CFPB permanently dropped its 2023 enforcement action against CAC in 2025. CAC will provide $60 million in cash restitution, $634 million in debt relief, an additional $15 million to the states, and implement injunctive lending reforms including loan off ramps, pre-loan disclosures, add-on packing safeguards, and a seven-year vehicle price cap. Note: this is a consumer-protection lending enforcement action, not a privacy matter; violation categories are best-fit mappings from the available taxonomy.

NJ

Match Group, Inc.

$650K

The New Jersey Attorney General and Division of Consumer Affairs announced that Match Group, Inc. will pay $650,000 and change its business practices to settle allegations that it misrepresented or failed to disclose its criminal background screening policies and practices to New Jersey users, violating the New Jersey Consumer Fraud Act and the Internet Dating Safety Act. Under a Consent Order, Match must accurately represent its screening policies, notify existing New Jersey members of updated disclosures within 150 days, and post clear and conspicuous disclosures and safety notifications about the limitations of criminal background screenings.

NJ

Glenmark, Lannett, Bausch, Apotex, Heritage, and Emcure

$96.5M

New Jersey and a coalition of states and territories obtained preliminary approval for a plan to distribute funds from settlements with generic drug manufacturers accused of conspiring to raise drug prices. The settlements total approximately $96.5 million, and eligible consumers may submit claims for compensation.

NJ

Amazon

On August 31, 2026, New Jersey Attorney General Jennifer Davenport and the Division of Consumer Affairs joined the FTC and a bipartisan coalition of 21 other states in suing Amazon, alleging that for over seven years the company secretly rigged its advertising auctions—converting advertised 'second price' auctions into first-price auctions with hidden 'soft reserve price' surcharges—overcharging more than 500,000 small- and medium-sized businesses and extracting tens of billions of dollars. The complaint alleges Amazon actively concealed the surcharges, gave false and misleading answers to advertisers who asked directly about the auction format, and applied inflated upcharges on high-volume shopping days like Prime Day and Black Friday. The lawsuit was just filed; no penalties or remedies have been imposed yet.

NJ

Meta Platforms, Inc.

A bipartisan coalition of state attorneys general led by New Jersey, California, Colorado, and Kentucky is taking Meta Platforms, Inc. to trial, alleging that Meta designed addictive features on Instagram and Facebook that harm minors' mental health, illegally collected data from children under 13 without the required protections under COPPA, and misled users about platform safety. Opening arguments begin August 18, 2026, in the U.S. District Court for the Northern District of California. No monetary penalty or final remedy has yet been imposed.

NJ

U.S. Department of Transportation

A coalition of 21 state attorneys general and Pennsylvania filed lawsuits against the Trump Administration, DOT, FMCSA, DHS, and AAMVA to prevent the unlawful demand for a database containing personal information of 17 million commercial driver's license holders. The lawsuits allege violations of federal privacy laws and the Administrative Procedure Act, and seek an emergency order to block the data transfer.