Health data privacy with AI starts before you press send – kevinmd.com
HHS Awards Almost $250 Million to Expand Addiction Treatment, Overdose Prevention and Mental Health Services – HHS.gov
Labcorp Settles Multistate Data Breach Investigation for $2.3 Million – The HIPAA Journal
Labcorp Settles Multistate Data Breach Investigation for $2.3 Million
A coalition of 44 state attorneys general has agreed to settle a multistate investigation of Laboratory Corporation of America (Labcorp) regarding a 2019 data breach at its debt collection company, American Medical Collection Agency (AMCA). Labcorp has agreed to pay $2,287,455, which will be divided among the 44 states participating in the action.
AMCA is a subsidiary of the debt collection company Retrieval-Masters Creditors Bureau (RMCB) and provides small debt collection services to healthcare organizations, including laboratories and medical testing facilities. The hacking incident was identified by RMCB on March 19, 2029, and the forensic investigation determined that a hacker breached the AMCA network around 8 months before the intrusion was detected. The hacker had access to the network from August 1, 2018, until March 30, 2019, and exfiltrated sensitive data including names, personal information, Social Security numbers, financial information, medical test information, and diagnostic codes.
The AMCA data breach was the largest data breach reported in 2019 by a HIPAA-regulated entity, affecting more than 27.5 million individuals, including more than 10.2 million Labcorp patients. The high cost of remediation forced AMCA to file for bankruptcy protection. AMCA was also investigated by the coalition, led by the Indiana, Texas, Connecticut, and New York attorneys general, and received permission from the bankruptcy court to settle the multistate action, filing for dismissal of the bankruptcy on December 9, 2020.
The settlement required AMCA to develop, implement, and maintain an information security program and implement a range of data security measures, including developing an incident response plan and appointing a qualified Chief Information Security Officer (CISO). A financial penalty of $21 million was suspended due to the financial position of the company.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
The investigation of Burlington, NC-based Labcorp was led by the attorneys general of Connecticut, Florida, Indiana, Illinois, Michigan, and Texas and identified potential violations of the Health Insurance Portability and Accountability Act (HIPAA) and state consumer protection and breach notification laws. The Labcorp settlement includes a financial penalty and injunctive relief. Labcorp must ensure that it does not misrepresent the extent to which it maintains and protects the privacy, security, and confidentiality of personal information (PI) and protected health information (PHI) and must implement a range of security measures, including but not limited to the following:
- Review, revise, and update its information security program.
- Employ an executive or officer as a CISO to oversee the implementation and maintenance of its information security program.
- Provide security awareness training to all personnel who have access to or responsibility for PI and/or PHI.
- Implement an incident response plan, which must include a plan for vendor security incidents.
- Ensure procedures are implemented for reporting vendor security incidents internally to senior management.
- Develop policies and procedures governing the collection, use, disclosure, and retention of PI and PHI, including specific policies and procedures for PI and PHI shared with debt collectors.
- Minimize the PI and PHI shared with debt collectors.
- Develop, implement, and maintain a vendor risk management program; maintain a vendor risk management team; and use security assessment and management tools for vendor assessment and monitoring, with specific requirements for debt collectors.
- Require all debt collectors to conduct risk assessments, and contractually require debt collectors to conduct penetration tests of systems containing PI and PHI, and annual SOC 2 Type 2 audits.
- Labcorp must also engage a third-party assessor to perform an information security assessment, with a focus on vendor risk management.
Labcorp was also named as a defendant in class action litigation against AMCA and other AMCA clients, and agreed to a $35,000,000 settlement earlier this year. The class action lawsuit is ongoing against other AMCA clients.
The post Labcorp Settles Multistate Data Breach Investigation for $2.3 Million appeared first on The HIPAA Journal.
