Labcorp Settles Multistate Data Breach Investigation for $2.3 Million

A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (Labcorp) regarding a 2019 data breach at its debt collection company, American Medical Collection Agency (AMCA). Labcorp has agreed to pay $2,287,455, which will be divided among the 44 states participating in the action.

AMCA is a subsidiary of the debt collection company Retrieval-Masters Creditors Bureau (RMCB) and provides small debt collection services to healthcare organizations, including laboratories and medical testing facilities. The hacking incident was identified by RMCB on March 19, 2029, and the forensic investigation determined that a hacker breached the AMCA network around 8 months before the intrusion was detected. The hacker had access to the network from August 1, 2018, until March 30, 2019, and exfiltrated sensitive data including names, personal information, Social Security numbers, financial information, medical test information, and diagnostic codes.

The AMCA data breach was the largest data breach reported in 2019 by a HIPAA-regulated entity, affecting more than 27.5 million individuals, including more than 10.2 million Labcorp patients. The high cost of remediation forced AMCA to file for bankruptcy protection. AMCA was also investigated by the coalition, led by the Indiana, Texas, Connecticut, and New York attorneys general, and received permission from the bankruptcy court to settle the multistate action, filing for dismissal of the bankruptcy on December 9, 2020.

The settlement required AMCA to develop, implement, and maintain an information security program and implement a range of data security measures, including developing an incident response plan and appointing a qualified Chief Information Security Officer (CISO). A financial penalty of $21 million was suspended due to the financial position of the company.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The investigation of Burlington, NC-based Labcorp was led by the attorneys general of Connecticut, Florida, Indiana, Illinois, Michigan, and Texas and identified potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and state consumer protection and breach notification laws. The Labcorp settlement includes a financial penalty and injunctive relief. Labcorp must ensure that it does not misrepresent the extent to which it maintains and protects the privacy, security, and confidentiality of personal information (PI) and protected health information (PHI) and must implement a range of security measures, including but not limited to the following:

  • Review, revise, and update its information security program.
  • Employ an executive or officer as a CISO to oversee the implementation and maintenance of its information security program.
  • Provide security awareness training to all personnel who have access to or responsibility for PI and/or PHI.
  • Implement an incident response plan, which must include a plan for vendor security incidents.
  • Ensure procedures are implemented for reporting vendor security incidents internally to senior management.
  • Develop policies and procedures governing the collection, use, disclosure, and retention of PI and PHI, including specific policies and procedures for PI and PHI shared with debt collectors.
  • Minimize the PI and PHI shared with debt collectors.
  • Develop, implement, and maintain a vendor risk management program; maintain a vendor risk management team; and use security assessment and management tools for vendor assessment and monitoring, with specific requirements for debt collectors.
  • Require all debt collectors to conduct risk assessments, and contractually require debt collectors to conduct penetration tests of systems containing PI and PHI, and annual SOC 2 Type 2 audits.
  • Labcorp must also engage a third-party assessor to perform an information security assessment, with a focus on vendor risk management.

Labcorp was also named as a defendant in class action litigation against AMCA and other AMCA clients, and agreed to a $35,000,000 settlement earlier this year. The class action lawsuit is ongoing against other AMCA clients.

The post Labcorp Settles Multistate Data Breach Investigation for $2.3 Million appeared first on The HIPAA Journal.

Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems

Notification letters are being mailed to individuals affected by data breaches at the pharmacy benefit management service provider MedImpact Healthcare Systems and the healthcare software company Rosch Visionary Systems.

MedImpact Healthcare Systems

MedImpact Healthcare Systems, a provider of pharmacy benefit management services to health plans, government entities, and self-insured employers, identified unauthorized activity within its computer network in October 2025. Immediate action was taken to secure its computer systems and prevent further unauthorized access, and an investigation was launched to determine the nature and scope of the incident.

The investigation was finalized on July 17, 2026, and the affected clients were informed about the data breach on August 13, 2026. Notification letters started to be sent to the affected individuals by MedImpact Healthcare on behalf of its affected clients on September 23, 2026. Data compromised in the incident included names in combination with some or all of the following: address, date of birth, subscriber number, Social Security numbers, health insurance information, health-related information such as prescription information, treatment information, dates of service, service locations, and provider names. The affected clients and number of affected individuals have not been publicly disclosed.

Individuals whose Social Security numbers were involved have been offered complimentary credit monitoring and identity theft protection services. At the time of issuing notification letters, no misuse of the affected data had been identified. The Qilin ransomware group claimed responsibility for the data breach and added MedImpact Healthcare to its dark web data leak site in October 2025. Qilin claimed to have exfiltrated sensitive data in the incident and threatened to leak the data if the ransom was not paid.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Rosch Visionary Systems

Rosch Visionary Systems, a Pennsylvania-based software company that provides allergy and immunotherapy management software for medical practices, has experienced a cybersecurity incident that compromised part of its computer network. The breach notifications sent to state attorneys general do not state when the breach occurred, when it was detected, or the nature of the unauthorized activity. Healthcare providers that use its software have been notified, and individual notification letters are being mailed to the affected individuals. Complimentary credit monitoring and identity theft protection services have been offered for 24 months.

The scale of the data breach and specific types of information involved are unclear. Healthcare provider clients known to have been affected include Allergy, Asthma and Food Allergy Centers and Texas Regional Asthma, Allergy & Immunology Center. This appears to have been a ransomware attack or data theft and extortion incident. A threat group called Lynx claimed responsibility for the cyberattack and alleged that sensitive data was stolen from Rosch Visionary Systems. The company is no longer listed on the Lynx data leak site, which suggests that a ransom payment was negotiated.

The post Data Breaches Announced by MedImpact Healthcare Systems; Rosch Visionary Systems appeared first on The HIPAA Journal.

Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits

Settlements have been agreed to resolve class action complaints against Wayne Memorial Hospital in Georgia and Regional Urology in Louisiana stemming from breaches of patients’ personal and protected health information.

Wayne Memorial Hospital Data Breach Settlement

Wayne Memorial Hospital Auxiliary, Inc. d/b/a Wayne Memorial Hospital, a Georgia healthcare provider, has agreed to settle a class action lawsuit over a 2024 data breach. Wayne Memorial Hospital identified a cybersecurity incident on or around June 3, 2024. The forensic investigation determined that an unauthorized third party had access to its network between May 30, 2024, and June 3, 2024, and potentially obtained patients’ personal and protected health information. Notification letters were mailed to the affected individuals in late August 2025.

Multiple class action lawsuits were filed in response to the data breach, alleging that the hospital was at fault for the data breach, as insufficient measures had been implemented to protect against unauthorized access to systems containing patient information. The lawsuits were consolidated as they all made similar claims. The consolidated lawsuit – Bates v. Wayne Memorial Hospital – is pending in the Superior Court of Wayne County, State of Georgia. The parties participated in mediation in May 2026 and reached agreement on the terms of a settlement that were acceptable to all parties. The settlement has now received preliminary approval from the court.

Wayne Memorial Hospital has agreed to pay attorneys’ fees and expenses, settlement administration costs, and service awards from the class representatives. Class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket expenses due to the data breach up to a maximum of $5,000 per class member. Alternatively, a claim may be submitted for a one-time, pro rata cash payment, estimated to be $25 per class member. The cash payments may be adjusted depending on the number of valid claims received. The deadline to object to the settlement and opt out is November 7, 2026. Claims must be submitted by December 7, 2026. The final fairness hearing has been scheduled for January 27, 2027.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Regional Urology Data Breach Settlement

Regional Urology, a private urology clinic in Northern Louisiana that operates under the name Ochsner LSU Health – Regional Urology, has agreed to settle class action litigation stemming from a data security incident first identified in October 2025. Regional Urology was a victim of a targeted cyberattack that exposed patients’ personal and protected health information. Data compromised in the incident included names, dates of birth, Social Security numbers, medical record numbers, and information related to the care provided.

The first class action lawsuit was filed by plaintiff Cathy Cowden on October 17, 2025. Three further class action lawsuits were filed over the data breach, which were consolidated as they made similar claims and had overlapping classes. The consolidated lawsuit – Clark, et al., v. Regional Urology, LLC, et al. – is pending in the District Court for the Parish of Caddo, Louisiana.

The plaintiffs alleged that the data breach should have been prevented and was due to the failure to implement reasonable and appropriate cybersecurity measures. The consolidated lawsuit asserted claims for negligence, breach of implied contract, unjust enrichment, breach of fiduciary duty, and declaratory judgment. The defendant denies all claims in the lawsuit, including fault, liability, and wrongdoing.

The parties agreed to attend mediation, and the terms of a settlement were agreed. The settlement has now been finalized and has received preliminary approval from the court. Under the terms of the settlement, class members may submit a claim for reimbursement of documented, unreimbursed out-of-pocket losses due to the data breach up to a maximum of $5,000 per class member. The expenses must have been incurred between October 5, 2025, and November 16, 2026. In addition, a claim may be submitted for one year of medical data monitoring services.

Individuals who do not submit a claim for losses and/or medical monitoring services may claim a one-time $40.00 cash payment. The deadline to object to the settlement and opt out is October 16, 2026. Claims must be submitted by November 16, 2026. The final fairness hearing has been scheduled for October 19, 2026.

The post Wayne Memorial Hospital; Regional Urology Settle Data Breach Lawsuits appeared first on The HIPAA Journal.