Can you delegate your data security duties? Lessons from the $2.3 Million Labcorp Settlement
On September 24, 2026, Labcorp settled with a coalition of 44 state attorneys general (AGs) for $2,287,455 over a 2019 data breach. The breach was not Labcorp’s, however, but AMCA’s: a company that provides small debt collection services to healthcare organizations, including laboratories and medical testing facilities, and to which Labcorp had outsourced patient billing. The AMCA breach potentially exposed the personal information of 27.5 million people, including 10.2 million Labcorp patients (43,666 of them in Connecticut). The multistate coalition of AGs previously settled with AMCA in 2021 after the company’s bankruptcy petition was dismissed, but that does not mean Labcorp was off the hook. In other words, Labcorp handed its patients’ data to a vendor, the vendor’s systems were infiltrated by a hacker, and seven years later Labcorp is signing the consent order—on top of a separate $35 million class-action settlement in the related litigation.
Your vendor was hacked, so why are you signing the consent order?
Because, as the Connecticut Attorney General's office put it, "data security is a non-delegable duty." Labcorp could outsource the billing, but it could not outsource its responsibility for overseeing its vendors. Perhaps this is why the settlement terms read like the vendor risk management program Labcorp should have had in 2019, particularly for a covered entity under the Health Insurance Portability and Accountability Act (HIPAA), including:
Developing an incident-response plan with internal reporting of vendor security events,
Minimizing data sharing with vendors,
Expanding its vendor risk management program to include a dedicated vendor-risk team,
Changes to its contracts with vendors, including provisions for cybersecurity standards, data segmentation (because debt collectors often aggregate data from multiple clients), vendor assessments and audits, and termination rights for noncompliance.
The Labcorp settlement is an important lesson for companies that outsource processing to third-party vendors, and particularly for companies that are covered entities or business associates under HIPAA: HIPAA compliance is not a toggle that you switch on. It requires an active vendor risk management. We will get into that next.
A Signed BAA is not a Vendor Management Program.
Signing a business associate agreement with a vendor is a required step before you share protected health information (PHI) with that vendor, but it does not relieve you of your vendor management obligations. This is both particularly challenging in our current cybersecurity environment and mission-critical. Indeed, the HIPAA Security Rule already says as much: a covered entity may share PHI with a business associate only after “satisfactory assurances” that the vendor will appropriately safeguard it, and the business associate agreement is simply the written form these assurances take.
What Labcorp learned, at the cost of a $2.3 million regulatory settlement plus a $35 million class-action settlement, is that “satisfactory assurances” are not a one-time event at signing. The U.S. Department of Health and Human Services’ proposed amendments to the HIPAA Security Rule (HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information, 90 Fed. Reg. 800, January 6, 2025) would require business associates to verify, in writing, at least every twelve months, that they have actually deployed the required technical safeguards. Although that rule is still pending (its final action date has been pushed to July 2027), we see 44 attorneys general did not wait for it.
So what does vendor management look like after the BAA is signed? Borrowing from the Labcorp consent order, at a minimum:
(1) a current inventory of every vendor that touches PHI, including your business associates’ own subcontractors;
(2) minimum-necessary data sharing, so that a debt collector or analytics vendor receives only the fields it needs;
(3) contract terms that address cybersecurity standards, data segmentation, audit rights, incident-reporting deadlines (potentially shorter than HIPAA’s 60-day outer limit), and the right to terminate for noncompliance;
(4) a named person inside the company who will monitor and exercise these rights; and
(5) an incident-response plan that treats a vendor’s breach as your breach.
For AI startups that touch healthcare or act as business associates for HIPAA-covered entities, these questions may reach you long before a regulator does—in a customer's security questionnaire, and in the BAA its counsel sends back marked up. Where is PHI stored, and who are your subprocessors? Do you have a BAA with each of them? When did you last audit them? How quickly will you notify us of a vendor incident? Luckily, the answers are the same ones Labcorp is now paying to build, and it is far cheaper to have them ready before someone asks (and certainly before your vendor experiences a data breach).