A massive breach at Labcorp’s debt collector exposed the personal data of more than 27.5 million people in 2019. Seven years later, a coalition of 44 states has secured a $2.3 million settlement and sweeping new safeguards to protect consumers’ sensitive medical and financial information. Between the period of August 2018 and March 2019, hackers infiltrated the systems of American Medical Collection Agency (AMCA), a third-party debt collector for Labcorp. The breach compromised Social Security numbers, payment card details, and medical test information tied to millions of patients, including 420,000 New Yorkers.
Despite warnings from banks, AMCA failed to detect the intrusion, leading to one of the largest healthcare-related data breaches in US history.
New York Attorney General Letitia James announced the settlement Wednesday, having joined a bipartisan coalition of 43 other state attorneys general to hold Labcorp accountable for the fallout of a 2019 breach tied to its debt collection vendor, American Medical Collection Agency (AMCA). The breach potentially exposed personal information belonging to over 27.5 million people across the country, including 10.2 million Labcorp patients specifically — 420,000 of whom lived in New York. A hacker accessed AMCA’s internal systems between August 1, 2018 and March 30, 2019, collecting customers’ personal information in the process, according to the settlement. The exposed data included Social Security numbers, payment card information, and details about medical tests and diagnostic codes tied to roughly 420,000 New Yorkers alone. In July 2026, her office secured $18 million from 23andMe over failures to protect customers’ genetic data. In November 2025, it secured $1.7 million from Illuminate Education following a breach of sensitive student data, and in October 2025, obtained $14.2 million from eight car insurance companies for failing to protect the private information of more than 825,000 New Yorkers.
AMCA, based in Elmsford, New York, specialized in small-balance medical debt collection primarily on behalf of laboratories and testing facilities like Labcorp, which is headquartered in Burlington, North Carolina. Despite multiple warnings from banks processing AMCA’s payments about a possible breach, the company failed to detect the intrusion at the time. The Labcorp settlement also fits into a broader pattern of data-breach enforcement James’s office has pursued in recent years.
Earlier settlements have also touched auto insurers and home security camera companies over similar data protection failures.

