
The $2.3 Million Lesson: Why Vendor Oversight Is the New Data Security Imperative
Between August 2018 and March 2019, attackers breached American Medical Collection Agency (AMCA), a debt collector serving Labcorp, exposing the data of 27.5 million people nationwide, including 10.2 million Labcorp patients. In September 2026, 44 state attorneys general announced a $2.3 million settlement with Labcorp, requiring sweeping data security reforms and stronger vendor oversight. The case shows that organizations cannot outsource data protection obligations: Labcorp was held accountable for AMCA’s weak security, including missing antivirus scans, ineffective SIEM logging, no web application firewall, and poor incident tracking. Regulators increasingly expect continuous vendor monitoring, contractual cybersecurity requirements, data minimization, and incident response plans that cover third parties. Companies should tier vendors by risk, audit compliance, limit shared data, and use technology that provides continuous visibility into data flows and user behavior.













