← Back to Blog

The $2.3 Million Lesson: Why Vendor Oversight Is the New Data Security Imperative

The $2.3 Million Lesson: Why Vendor Oversight Is the New Data Security Imperative

Between August 2018 and March 2019, attackers breached American Medical Collection Agency (AMCA), a debt collector serving Labcorp, exposing the data of 27.5 million people nationwide, including 10.2 million Labcorp patients. In September 2026, 44 state attorneys general announced a $2.3 million settlement with Labcorp, requiring sweeping data security reforms and stronger vendor oversight. The case shows that organizations cannot outsource data protection obligations: Labcorp was held accountable for AMCA’s weak security, including missing antivirus scans, ineffective SIEM logging, no web application firewall, and poor incident tracking. Regulators increasingly expect continuous vendor monitoring, contractual cybersecurity requirements, data minimization, and incident response plans that cover third parties. Companies should tier vendors by risk, audit compliance, limit shared data, and use technology that provides continuous visibility into data flows and user behavior.

The Breach That Started It All

In August 2018, a hacker quietly slipped into the internal systems of the American Medical Collection Agency (AMCA), a New York-based medical debt collector. The intruder remained undetected for approximately eight months, until March 2019. During that time, the attacker exfiltrated sensitive files containing names, Social Security numbers, financial information, diagnosis codes, and medical test details — not just from AMCA's own records, but from the millions of patients whose data AMCA had been entrusted to process on behalf of its clients.

AMCA's largest client was Labcorp, a major medical testing and diagnostics company headquartered in Burlington, North Carolina. Labcorp had contracted with AMCA to pursue outstanding customer debts related to its medical testing services, sharing the personal and protected health information of its patients in the process. When the breach was finally discovered, it had affected over 27.5 million individuals nationwide, including 10.2 million Labcorp patients. AMCA filed for bankruptcy weeks later and ultimately ceased operations.

In September 2026, a bipartisan coalition of 44 state attorneys general announced a $2.3 million settlement with Labcorp, resolving a multistate investigation into the 2019 breach. The agreement requires Labcorp to overhaul its data security practices and implement sweeping reforms to its vendor management program.

Anatomy of a Failure

The AMCA breach exposed severe technical and governance deficiencies at multiple levels.

At the technical level, AMCA's security infrastructure was woefully inadequate. The company was not running an antivirus scanner or file system scans, and its Security Information and Event Management (SIEM) system was ineffective because it was not logging server activity. There was no web application firewall installed, and traffic on the web server was not being logged, allowing malicious scripts to persist undetected. Despite receiving numerous warnings from banks that processed its payments about potential fraudulent activity, AMCA failed to detect the intrusion. It took an unrelated security firm — not AMCA's own security team — to identify the breach after it had already been ongoing for months.

At the governance level, the investigation revealed that Labcorp itself bore significant responsibility. The attorneys general contended that Labcorp should have done more to police AMCA's security practices. As Colorado Attorney General Phil Weiser put it: "While companies can contract with vendors, they cannot shift data security legal obligations to a contractor or third party. It is critical that businesses properly vet their vendors and ensure that information shared with those vendors will be kept secure." The investigation also found that Labcorp lacked procedures and processes related to audit logs, access reports, and security incident tracking reports.

The Regulatory Reckoning

The Labcorp settlement arrives amid a broader regulatory shift. Regulators including the FCC and ICO are increasingly emphasizing a company's obligation to monitor its service providers for cybersecurity compliance, recognizing that many data breaches occur not at the company that owns the data, but at its third-party vendors.

In 2025, 19% of legal matters reported by one major law firm originated from a third-party vulnerability or supply chain breach — a sharp increase from just 2% the previous year. The ICO has begun directly penalizing processors for security failures and is increasingly asking data controllers for evidence of due diligence performed at vendor onboarding, testing the appropriateness of third parties and demanding proof of ongoing annual reviews. The 2026 Verizon Data Breach Investigations Report found that third parties were involved in 48% of breaches analyzed, a 60% increase from the previous dataset.

The message from regulators is clear: data protection obligations cannot be outsourced. Organizations remain legally and reputationally accountable for the sensitive data they share with vendors, regardless of where a breach technically occurs.

Five Practical Recommendations for Enterprises

Based on the Labcorp/AMCA case and current best practices, organizations should take the following steps to strengthen their vendor risk posture.

1. Shift from annual reviews to continuous monitoring. Annual vendor assessments go stale quickly — a vendor can pass an assessment in January, expose a cloud service in February, and suffer credential theft in March, yet not be formally reviewed again until the following year. Risk-based, trigger-driven monitoring should replace calendar-based reviews, with any meaningful change in a vendor's risk profile automatically reopening scrutiny.

2. Tier vendors by risk and apply differentiated oversight. Not all vendors warrant the same level of scrutiny. A tiered model classifies vendors based on inherent risk and business impact, focusing resources on high-risk relationships that process sensitive data or integrate directly with critical systems. For debt collectors and other specialized vendors handling financial and health data, organizations should require contract inventories, enforce cybersecurity standards through contracts, mandate data segmentation, and include the right of termination for noncompliance.

3. Implement robust incident response plans that cover vendor security events. The Labcorp settlement specifically requires an incident response plan that includes internal reporting of vendor security events to senior management. Organizations should ensure that their IR plans explicitly address third-party incidents, with defined escalation paths and decision-making authority.

4. Limit data sharing to the minimum necessary. Reducing the volume and sensitivity of data shared with vendors directly reduces breach impact. The settlement requires Labcorp to minimize data sharing while balancing the legitimate needs of debt collectors to fulfill their legal obligations. This principle — data minimization — should apply across all vendor relationships.

5. Deploy technology that provides visibility into data flows and user behavior. Traditional rule-based DLP tools often cannot detect novel exfiltration methods or adapt to evolving threats. Organizations should consider AI-powered monitoring solutions that provide continuous visibility. For example, PrivateDLP uses AI-driven screenshot auditing to detect policy violations and data leakage in real time, operating with enterprise-approved LLM models and immediate screenshot deletion to protect employee privacy. In the vendor risk context specifically, the ability to monitor what data is being accessed, copied, or transferred — whether by internal staff or in connection with vendor interactions — is essential for maintaining the continuous oversight that regulators now expect.

Conclusion

The Labcorp/AMCA settlement is a watershed moment in vendor risk accountability. It reinforces that data security is not a contractual checkbox but a continuous obligation. The technical failures at AMCA — no SIEM, no antivirus, no web application firewall — were the proximate cause of the breach, but the underlying governance failure was Labcorp's inadequate vendor oversight. As regulators intensify scrutiny of third-party relationships and as supply chain breaches continue to rise, organizations that treat vendor risk management as a one-time onboarding exercise will find themselves increasingly exposed — legally, financially, and reputationally. The path forward requires continuous monitoring, contractual enforcement, data minimization, and technology that provides the visibility needed to act before a vendor incident becomes your own.

← Back to Blog