1,634 enforcement actions from 16 federal and state jurisdictions. Every event traced back to its official government source.
1,634
Total Actions
16
Jurisdictions
$49.9B+
Total Fines Tracked
Labcorp agreed to pay $2,287,455 and make security and vendor-management reforms following a 2019 breach of its debt collector AMCA that potentially exposed personal information of more than 27.5 million people, including Labcorp patients’ sensitive medical information. The settlement requires stronger security and incident response practices, limits on vendor data sharing, enhanced vendor oversight, contractual cybersecurity requirements, and an independent security assessment.
$2.3M
New York and a bipartisan coalition of 43 other attorneys general reached an agreement with Laboratory Corporation of America (Labcorp) following a 2019 breach at its debt-collection vendor, AMCA, that potentially exposed personal information of more than 27.5 million people. Labcorp will pay $2,287,455 to the states and implement extensive security and vendor-risk reforms.
$2.3M
Connecticut Attorney General William Tong led a 44-attorney-general coalition settlement with Laboratory Corporation of America over the 2019 AMCA breach, which potentially exposed personal information of more than 27.5 million people, including 10.2 million Labcorp patients. Labcorp will pay $2,287,455 and implement enhanced vendor-risk management, information-security, and oversight measures.
$2.3M
Colorado and a bipartisan coalition of attorneys general reached a $2,287,455 settlement with Laboratory Corporation of America over the 2019 data breach at its debt collector, American Medical Collection Agency. The settlement requires stronger vendor risk management and information security practices, with particular requirements for medical debt collectors.
$2.3M
Laboratory Corporation of America Holdings agreed to pay $2,287,455 to participating states and strengthen its security and vendor-management practices following an investigation into the 2019 breach at its debt-collection vendor, AMCA. The breach potentially exposed information of more than 27.5 million people nationwide, including sensitive information belonging to approximately 10.2 million LabCorp patients.
$2.3M
Connecticut joined 39 other states and the federal government in a $384 million False Claims Act settlement with Abbott Laboratories over allegations that the company failed to manufacture powder infant formula and nutritional therapy products in compliance with federal and state requirements at its Sturgis, Michigan, and Casa Grande, Arizona facilities. Abbott allegedly manufactured formula in conditions that risked microorganism contamination and failed to disclose contamination test results to the FDA during 2019 and 2022 inspections. The settlement resolves claims that Abbott caused false claims to be submitted to the WIC program and state Medicaid programs between January 1, 2018, and December 31, 2022.
$384.2M
Abbott Laboratories agreed to pay more than $384 million — including $977,558 to Oregon — to resolve allegations that it sold powder infant formula and nutritional therapy products made in unsafe manufacturing conditions to Medicaid and food assistance programs such as WIC between January 2018 and December 2022. Investigators found Abbott failed to maintain manufacturing equipment and control water at its Sturgis, Michigan, and Casa Grande, Arizona, facilities, and withheld test results showing contamination during FDA inspections in 2019 and 2022. The settlement was negotiated by the National Association of Medicaid Fraud Control Units on behalf of the federal government and 39 states.
$384.2M
BMG of Kansas, Inc. (Health Plan, KS) reported a HIPAA breach affecting 1,327 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Manhattan Retirement Foundation d/b/a Meadowlark Hills (Healthcare Provider, KS) reported a HIPAA breach affecting 14,442 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
AltaMed Health Services Corporation (Healthcare Provider, CA) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Couve Healthcare Consulting, LLC DBA Evergreen Healthcare Group (Business Associate, WA) reported a HIPAA breach affecting 11,795 individuals. Breach type: Hacking/IT Incident. Location of breached information: Electronic Medical Record.
QualDerm Partners, LLC (Healthcare Provider, TN) reported a HIPAA breach affecting 3,117,874 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
The Center for Advanced Eye Care (Healthcare Provider, ME) reported a HIPAA breach affecting 9,300 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.
Option Care Health, Inc. (Healthcare Provider, IL) reported a HIPAA breach affecting 2,086 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
VNS Behavioral Health Inc. (“VNS Health”) (Healthcare Provider, NY) reported a HIPAA breach affecting 739 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email.
Emanuel Medical Center (Healthcare Provider, GA) reported a HIPAA breach affecting 28,963 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
44North (Business Associate, MI) reported a HIPAA breach affecting 2,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Desktop Computer.
Easterseals Northeast Indiana (Healthcare Provider, IN) reported a HIPAA breach affecting 3,158 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Wee Care Pediatrics, LLC (Healthcare Provider, UT) reported a HIPAA breach affecting 2,127 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
National Association on Drug Abuse Problems (Healthcare Provider, NY) reported a HIPAA breach affecting 90,000 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Cedar Valley Services (Healthcare Provider, MN) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Academic Urology & Urogynecology of Arizona (Healthcare Provider, AZ) reported a HIPAA breach affecting 73,281 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Resource Corporation of America (Business Associate, TX) reported a HIPAA breach affecting 501 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
VPS Medical PLLC (Healthcare Provider, PA) reported a HIPAA breach affecting 4,600 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
Cedar Point Health, LLC (Healthcare Provider, CO) reported a HIPAA breach affecting 23,114 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
University Spine Center (Healthcare Provider, NJ) reported a HIPAA breach affecting 582 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server, Other.
Alexes Hazen MD, PLLC (Healthcare Provider, NY) reported a HIPAA breach affecting 500 individuals. Breach type: Hacking/IT Incident. Location of breached information: Email, Network Server.
First Choice Community Home Care, Inc. (Healthcare Provider, TX) reported a HIPAA breach affecting 725 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
BlueCross BlueShield of Tennessee, Inc. (Business Associate, TN) reported a HIPAA breach affecting 1,670 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
ApolloMD Business Services, LLC (Business Associate, GA) reported a HIPAA breach affecting 626,540 individuals. Breach type: Hacking/IT Incident. Location of breached information: Network Server.
All data sourced from official government enforcement pages.