Laboratory Corporation of America Data Breach Exposes Social Security Numbers and Medical Information

Published: 30 September 2026
Healthcare data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: 22nd March 2026

A 2019 breach at Labcorp’s billing vendor, AMCA, exposed the personal and medical information of over 27.5 million people nationwide, including 10.2 million Labcorp patients. Exposed data included Social Security numbers, financial details, and medical information. Labcorp has now settled with 44 state attorneys general. Affected individuals should monitor credit reports and consider a credit freeze immediately.

CompanyLaboratory Corporation of America
IndustryHealthcare
Data Types ExposedFull Names, Social Security Numbers, Dates of Birth, Financial Account Information, Medical Information
People Affected27.5 million individuals
Attack MethodThird-Party Vendor Breach
Regulators NotifiedVermont Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Labcorp Data Breach?

Laboratory Corporation of America, widely known as Labcorp, is at the center of a resolved multistate investigation tied to a major data breach. The breach did not happen inside Labcorp’s own systems. Instead, it occurred at a billing vendor the company used, Retrieval-Masters Creditors Bureau, which operated under the name American Medical Collection Agency, or AMCA.

AMCA served as a debt collector for Labcorp and handled sensitive patient billing information on Labcorp’s behalf. In 2019, attackers gained unauthorized access to AMCA’s systems. Because AMCA stored data belonging to Labcorp patients, that access exposed personal and medical information far beyond AMCA’s own customer base.

Following the breach, AMCA filed for bankruptcy. However, that bankruptcy petition was later dismissed, which allowed a coalition of state attorneys general to proceed with their investigation. As a result, a 44-state coalition eventually reached a settlement with AMCA in 2021.

The investigation did not stop there. Regulators determined that Labcorp, as the company whose patients’ data was exposed, bore responsibility for vendor oversight. This led to a separate multistate settlement directly with Labcorp, announced through the Nebraska Attorney General’s office and other participating states.

Investigators concluded that data security obligations cannot simply be handed off to a vendor. Even though Labcorp contracted with AMCA to perform debt collection work, the duty to protect patient data remained with Labcorp itself. This finding shaped the terms of the eventual settlement.

Who was affected?

The Labcorp data breach affected an enormous number of people across the country. According to the settlement announcement, the AMCA breach potentially exposed personal information belonging to more than 27.5 million individuals nationwide.

Of that total, roughly 10.2 million were specifically identified as Labcorp patients. This means the exposure reached a substantial share of people who had simply used Labcorp for routine medical testing or diagnostic services.

The breach’s reach extended into individual states as well. For example, 9,777 Nebraska residents were among those whose information was potentially compromised. Because Labcorp operates nationwide, patients in nearly every state could have been affected.

It has not been publicly disclosed whether minors were among the affected patients. However, given that lab testing services are used by people of all ages, it is reasonable for families to check whether any household members could be impacted.

What Information Was Potentially Exposed?

The data involved in this breach was particularly sensitive because it combined financial billing details with medical service information. Because AMCA handled debt collection for lab testing services, the exposed data reflected both healthcare and financial categories.

  • Full names
  • Social Security numbers
  • Dates of birth
  • Financial account and billing information
  • Medical information related to lab services provided by Labcorp

This combination of data creates significant risk for affected individuals. Social Security numbers, in particular, are one of the most valuable pieces of information for identity thieves because they can be used to open new credit accounts or file fraudulent tax returns.

In addition, because medical information was involved, there is a heightened risk of medical identity theft. This occurs when someone uses stolen information to receive medical treatment or submit fraudulent insurance claims under another person’s name. Victims may not discover this type of fraud until they receive a confusing medical bill or see unfamiliar claims on an insurance statement.

What is the company doing?

As part of the resolution of the multistate investigation, Labcorp agreed to a formal settlement with the coalition of state attorneys general. Under the agreement, Labcorp will pay a total of $2,287,455.00 to the participating states, with $16,661.00 allocated specifically to Nebraska.

Beyond the monetary payment, the settlement requires Labcorp to strengthen how it manages vendors, especially those handling medical debt collection. This includes building out a more robust incident response plan that requires vendors to report security events internally.

Labcorp also agreed to limit how much data it shares with vendors going forward, while still allowing debt collectors to meet their legal obligations. In addition, the company must expand its vendor risk management program, including creating a dedicated internal team and using formal tools to evaluate vendor security practices.

The settlement further requires Labcorp to maintain a full inventory of vendor contracts and enforce cybersecurity standards through those contracts. Vendors handling data for multiple clients must now keep that data properly segmented. Labcorp must also require vendors to undergo regular assessments and audits, with the right to terminate any vendor relationship for non-compliance.

Finally, Labcorp is required to hire an independent third-party assessor to evaluate its information security program, with particular focus on vendor risk management. Separately, Labcorp has also filed a formal data breach notification with the Vermont Attorney General, reflecting its continued compliance obligations tied to this incident.

What Should Affected Individuals Do?

Monitor Your Credit Reports Regularly

Because Social Security numbers were exposed in this breach, affected individuals should check their credit reports on a regular basis. Look for unfamiliar accounts, unexpected credit inquiries, or any activity you do not recognize.

You can request a free credit report from each of the three major credit bureaus. Reviewing these reports every few months makes it easier to catch fraudulent activity early, before it causes lasting financial damage.

Consider a Credit Freeze or Fraud Alert

Given the exposure of Social Security numbers, placing a credit freeze is one of the strongest protective steps available. A freeze prevents new creditors from accessing your credit file, which makes it much harder for identity thieves to open accounts in your name.

Alternatively, a fraud alert requires lenders to take extra verification steps before approving new credit. Both options are free to set up. Because this breach involved sensitive identifiers, taking one of these steps is strongly recommended.

Watch for Signs of Medical Identity Theft

Since medical information tied to Labcorp services was exposed, affected individuals should carefully review any insurance statements or medical bills they receive. Look for services or claims you do not recognize.

If you notice suspicious medical activity, contact your insurance provider immediately. This helps prevent inaccurate information from being added to your medical records, which can be difficult and time-consuming to correct later.

Stay Alert for Phishing Attempts

Following any large-scale data breach, scammers often use stolen information to craft convincing phishing emails or phone calls. Affected individuals should be cautious of unexpected messages asking for personal or financial details.

Legitimate companies rarely ask for sensitive information through email or text. If you receive a suspicious message referencing this breach, avoid clicking links and instead contact the organization directly through a verified phone number or website.

Consult a Data Breach Attorney if You Suspect Harm

If you believe you have experienced financial loss, medical billing errors, or identity theft linked to this breach, it may be worth speaking with a data breach attorney. Many offer free case evaluations to help you understand your options.

An attorney can help you determine whether you qualify for compensation and guide you through the claims process. This is especially useful if you are unsure how the breach has affected you personally.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from Vermont Attorney General

Related Data Breaches

View the full list of tracked data breaches →