
More than 17,000 Hawaiʻi residents had their personal information caught up in a years-old data breach tied to Labcorp, and the state has now joined dozens of others in a settlement meant to force the lab-testing giant to clean up how it handles outside vendors. The breach traces back to 2019, when a billing vendor's systems were compromised, exposing Social Security numbers, payment details, and medical test and diagnostic codes for patients across the country.
The Hawaiʻi Department of Commerce and Consumer Affairs Office of Consumer Protection joined 43 other attorneys general in the settlement, according to KHON2. The agreement involves Laboratory Corporation of America, better known as Labcorp, after the breach occurred at Retrieval Masters Creditors Bureau, doing business as American Medical Collection Agency, the outlet reports. Reporting on the size of the payout varies: KHON2's headline describes the deal as a $2.3 billion settlement, while the Connecticut Office of the Attorney General and the New York Attorney General both put the multistate payment at $2,287,455.
What the Breach Exposed
The scope of who was affected also depends on which account you read. KHON2 reports the breach potentially exposed personal information belonging to more than 27.5 million people nationwide, while BankInfoSecurity separately reports the hack affected more than 10.2 million Labcorp patients specifically, and also cites a figure of about 27.5 million people nationwide overall. TechTarget, meanwhile, reports the underlying incident affected more than 21 million individuals from August 2018 to March 2019, including more than 10 million Labcorp patients. Compromised data included Social Security numbers, payment information, and medical test and diagnostic codes, according to TechTarget.
Closer to home, KHON2 reports the breach included 17,347 Hawaiʻi residents. Mana Moriarty said people in Hawaiʻi should feel confident their personal and health information is protected, per the outlet's report.
New Rules for Labcorp's Vendors
Beyond the payment, the settlement requires Labcorp to develop or expand an information security program, including an incident-response plan specifically for vendor security events, KHON2 reports. The company must also limit the amount of data it shares with vendors, though debt collectors may still receive the data needed to meet their legal obligations, per the same account.
The station's report also details expanded vendor-risk management requirements: Labcorp must build out a dedicated team, evaluation tools and compliance checks, and add new cybersecurity requirements for medical debt collectors covering contracts, data separation, assessments and audits. Separately, BankInfoSecurity reports Labcorp must minimize the amount of data shared with vendors and overhaul its data-security practices, including employing a chief information security officer. The Colorado Attorney General notes Labcorp must also hire a third-party assessor to evaluate its information security and vendor-risk management.
A Second Settlement, and an Earlier One That Fell Apart
This isn't the first time regulators have gone after the company behind the breach. In 2021, 41 attorneys general reached a multistate settlement with AMCA that initially held the company liable for a $21 million payment, but that sum was later suspended because of AMCA's financial troubles, according to TechTarget. That earlier deal required AMCA to create an incident-response plan and hire a third-party assessor, mirroring some of the terms now imposed on Labcorp itself.
Labcorp has also agreed to a separate $35 million settlement in a related class-action lawsuit, which received final approval on August 20, according to Settlement Insight. That outlet reports the certified class included 11,825,034 potential members. A related class-action lawsuit remains ongoing with other AMCA client covered entities, per the seed reporting.
The Bigger Picture for Health Data Oversight
The Maryland Attorney General's office framed the settlement as a broader statement that HIPAA-covered entities have a duty both to protect personal and protected health information and to oversee the vendors entrusted with that data. The settlement itself clarified that HIPAA-covered organizations cannot shift responsibility for HIPAA compliance onto their vendors, according to the seed report.









