Office of the Vermont Attorney General

09/24/2026 | Press release | Archived content

Attorney General Clark Announces Multistate Settlement with Labcorp Over the American Medical Collection Agency Data Breach

Attorney General Charity Clark today announced that Vermont, as part of a coalition of 44 attorneys general, has settled with the Laboratory Corporation of America ("Labcorp") resolving the multistate investigation into the 2019 data breach at Labcorp's debt collector, Retrieval-Masters Creditors Bureau d/b/a American Medical Collection Agency ("AMCA"). As part of the settlement, Labcorp will make a payment of $ 2,287,455.00 to the states, including $15,533 to Vermont.

The AMCA breach potentially exposed the personal information of over 27.5 million individuals throughout the United States, including 10.2 million Labcorp patients, 948 of which are Vermont residents. The multistate coalition settled with AMCA in 2021 after the company's bankruptcy petition was dismissed.

Today's settlement stands for the premise that HIPAA-covered entities have a duty to protect personal and protected health information and oversee vendors entrusted with that information. The settlement provides strong requirements around vendor management, especially medical debt collection including:

  • Developing certain aspects of the company's information security program, such as an incident response plan that includes internal reporting of vendor security events;

  • Minimizing the sharing of data with vendors while balancing certain needs of debt collectors to meet their legal obligations;

  • Expanding the vendor risk management program to include requiring a dedicated team, employing tools to evaluate vendors, and verifying vendor compliance;

  • Adding specific requirements for debt collectors as a specialized subset of vendors, including maintaining contract inventories, enforcing cybersecurity standards through contract, segmenting data which is often aggregated by debt collectors for multiple clients, and requiring debt collectors to perform assessments and audits, and including the right of termination for non-compliance; and

  • Hiring a Third-Party Assessor to perform an information security assessment with a focus on vendor risk management.

Joining Attorney General Clark in reaching this settlement are the attorneys general of Alaska, Alabama, Arizona, Arkansas, Colorado, Connecticut, the District of Columbia, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Michigan, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Virginia, Washington, Wisconsin, and West Virginia.

Office of the Vermont Attorney General published this content on September 24, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 28, 2026 at 14:21 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]