Nadia Dubois
September 25, 2026
12 min read
Wisconsin has signed on to a 44-state settlement with Laboratory Corporation of America Holdings, better known as Labcorp, closing the book on a 2019 data breach that exposed medical and financial records tied to more than 27.5 million people nationwide. State officials confirmed on September 24-25, 2026, that Wisconsin joins a coalition led by New York Attorney General Letitia James, which secured roughly $2.3 million in payments and a rewrite of Labcorp’s vendor security rules. Local coverage from outlets including WXOW, the Jacksonville Journal-Courier, Daily Dodge, FOX5 Vegas, Audacy, and NottinghamMD.com put the number of affected Wisconsin residents at 16,615.
The settlement does not resolve a new breach. It closes out one of the largest healthcare-adjacent data exposures of the past decade, one that originated not at Labcorp itself but at a third-party debt collector the company relied on to chase down unpaid lab bills. Seven years, one bankruptcy, and two rounds of multistate litigation later, the case has become a reference point for how regulators now think about vendor risk in healthcare.
Don’t miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
What the Wisconsin-Labcorp Settlement Actually Covers
According to the New York Attorney General’s office, Labcorp will pay approximately $2,287,455 across the 44 participating jurisdictions, which include 43 states plus the District of Columbia. New York’s individual share was $89,178, a figure the state’s press release cited directly, giving a sense of how the total was apportioned by population and number of residents affected. Wisconsin’s specific dollar allocation was not broken out in the multistate announcement, but the state is listed among the participating attorneys general alongside Alabama, Illinois, Michigan, Ohio, Texas, and dozens of others.
Money is the smaller part of the deal. The bulk of the settlement is a set of binding operational changes Labcorp must make to how it manages outside vendors that touch patient data, changes that regulators frame as the real deterrent for future incidents involving the dark web monitoring and identity-theft risks that follow large health data exposures.
How Many Wisconsin Residents Were Affected
Wisconsin outlets reporting on the settlement put the state’s affected population at 16,615 residents, a subset of the more than 27.5 million people nationwide whose information was potentially exposed when the underlying breach occurred. That national figure comes directly from the New York Attorney General’s announcement, which also broke out that roughly 10.2 million of those individuals were Labcorp patients specifically, with the remainder tied to other laboratory and medical-testing clients of the same debt collector.
For comparison, New York’s own breakdown listed 420,000 affected residents in that state alone, meaning Wisconsin’s 16,615 figure sits well below the largest-hit states on a per-capita basis. The gap illustrates how unevenly a single vendor breach can land: the total customer overlap between Labcorp, its debt collector, and each state’s population determined exposure, not any decision Wisconsin regulators made.
Inside the 2019 Breach That Started It All
The breach did not happen inside Labcorp’s own network. It happened at American Medical Collection Agency (AMCA), a small-balance medical debt collector based in Elmsford, New York, that Labcorp and other laboratory companies used to pursue unpaid bills. Per the New York Attorney General’s account, a hacker gained access to AMCA’s internal systems between August 1, 2018, and March 30, 2019, and was able to collect customer personal information during that window.
What makes the case notable from a security standpoint is the detection failure. Banks that processed AMCA’s payment transactions flagged unusual card activity and warned the company about a potential intrusion, according to the New York Attorney General’s office, but AMCA failed to catch the breach in time. The exposed data included Social Security numbers, payment card information, and the names of medical tests and diagnostic codes tied to each patient, a combination regulators have repeatedly described as especially sensitive because it links financial identity theft risk to protected health information.
Labcorp was not the only major lab company caught in the AMCA fallout. Quest Diagnostics also used AMCA for debt collection, and reporting on the broader 2019 incident put Quest’s exposure at roughly 11.9 million patients, on top of the roughly 7.7 million to 10.2 million Labcorp patients cited across different points in the investigation. AMCA itself filed for bankruptcy within months of the breach becoming public, a collapse that later shaped how regulators could actually collect on penalties against the collector.
Why It Took Seven Years to Reach This Point
The 2026 Labcorp settlement is not the first legal action to come out of the AMCA breach. In 2021, the same coalition of state attorneys general reached a settlement directly with AMCA that included a $21 million judgment, but that payment was suspended because AMCA’s bankruptcy left the collector unable to pay. Regulators then shifted their investigation toward Labcorp itself, examining how the healthcare company vetted, contracted with, and monitored the vendor that ultimately lost control of its customers’ data.
That shift in target, from the breached vendor to the company that hired the vendor, is the throughline of the case. It took years of investigation to build the record establishing that Labcorp’s vendor-oversight practices, not just AMCA’s security failures, contributed to the scale of the exposure. The resulting settlement functions less like a breach-notification penalty and more like a vendor-risk-management enforcement action, similar in structure to cases building around third-party risk in sectors well beyond healthcare, including the kind of supply-chain scrutiny now common in software vulnerability disclosure and platform security incidents.
The 44-State Coalition Behind the Deal
New York led the investigation, with Attorney General Letitia James’s office coordinating a bipartisan group that, per the official announcement, included Alabama, Alaska, Arizona, Arkansas, Colorado, Connecticut, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, Wisconsin, West Virginia, and the District of Columbia.
James described corporations as bearing a responsibility to protect customers’ private data, especially sensitive medical information, and said millions of patients’ private health information was potentially exposed because of Labcorp’s failures to protect its customers, adding that the investigation would force the company to make critical changes to prevent a repeat incident, according to her office’s September 24 announcement. Connecticut Attorney General William Tong’s office and Maryland Attorney General Anthony Brown’s office both issued parallel statements emphasizing the same reform package: stronger vendor oversight, reduced data sharing, enforceable contract terms, mandatory audits, and independent third-party review.
New York’s Enforcement Pattern: A Comparison Table
The Labcorp case is not an isolated action. New York’s Attorney General has run a string of data-protection settlements over the past 18 months, and laying them side by side shows a consistent enforcement pattern: target the company that collected the data, not just the vendor or hacker who exposed it.
Every case in that table shares a structure with the Labcorp settlement: a corporation is held accountable for how a vendor, partner, or downstream system handled consumer data, rather than being let off the hook because a third party was the direct point of compromise. That pattern extends well past healthcare and mirrors enforcement trends seen after other high-profile breaches covered on this site, including the Gyazo breach affecting 23.6 million users and continued fallout from incidents tied to groups like ShinyHunters.
Timeline: From Breach to Settlement
What Labcorp Must Change: The Security Reforms
The non-monetary terms of the settlement read like a vendor-risk-management checklist, and regulators have been explicit that this is the point. Under the agreement, Labcorp must improve its information security program and build an incident-response plan that specifically accounts for vendor-side security breaches, not just intrusions on its own network. The company also has to minimize how much personal and health information it shares with debt collectors in the first place, while still meeting collectors’ legal recordkeeping obligations.
Beyond data minimization, Labcorp must expand its vendor risk management program to include a dedicated internal team, tools for evaluating vendor security postures, and ongoing verification that vendors actually comply with the standards they agree to. New requirements for debt collectors specifically include enforceable cybersecurity clauses written into contracts, mandatory segmentation of data that collectors often pool across multiple clients, required security assessments and audits, and a contractual right for Labcorp to terminate any vendor that fails to meet those standards. The company must also hire an independent third-party assessor to review its vendor-risk practices going forward, giving regulators an ongoing compliance check rather than a one-time fix.
Market Impact: What This Means for Labcorp and the Diagnostics Industry
Financially, $2.3 million is immaterial for a company the size of Labcorp, which operates one of the largest clinical laboratory networks in the country and trades on the New York Stock Exchange under the ticker LH. The settlement’s real cost sits in the operational overhead of standing up a formal vendor risk management function, staffing a dedicated oversight team, and funding recurring third-party assessments, audits, and penetration testing across every debt-collection vendor in its network.
The bigger signal for the broader diagnostics and healthcare-services industry is that state regulators are now willing to spend years building a vendor-liability case even when the breached party itself, AMCA, has already gone bankrupt and can’t meaningfully pay. That sets a precedent: companies that outsource billing, collections, or any function touching protected health information can expect scrutiny to follow the data controller, not just the breached processor. Compliance teams at hospital networks, insurers, and lab companies are likely to treat this case as a template for the kind of contract language and audit cadence regulators now expect, alongside standard technical defenses like the layered access controls increasingly required across sectors handling sensitive user data.
Competitive Comparison: Labcorp vs. Quest Diagnostics’ Exposure
Quest Diagnostics shared the same vendor and, according to reporting on the broader 2019 incident, a larger raw number of affected patients, roughly 11.9 million compared with the 10.2 million cited for Labcorp in the New York Attorney General’s announcement. Yet the September 2026 multistate settlement is specifically with Labcorp, not a joint action covering both companies. That divergence matters for anyone tracking corporate accountability in the space: two companies exposed through the identical AMCA breach have, so far, faced separate and different regulatory timelines, which suggests Quest’s own multistate exposure, if it exists, may still be working through investigation rather than settlement.
For healthcare compliance officers, the takeaway is that shared-vendor exposure does not guarantee identical regulatory outcomes. Each company’s contract terms, internal monitoring, and cooperation with investigators appear to shape how quickly, and how expensively, a case resolves.
Historical Context: Vendor Breaches Keep Outpacing Direct Attacks
The Labcorp case fits a pattern that has defined healthcare data security for most of the past decade: the weakest link is rarely the hospital, lab, or insurer’s own network. It’s the smaller, less-resourced vendor sitting downstream, whether that’s a debt collector, a billing processor, or a cloud storage provider. AMCA was a mid-sized collections firm that never had the security budget of the healthcare giants it served, and that mismatch is exactly what regulators are now trying to close through contractual mandates rather than hoping vendors self-improve.
This mirrors broader findings from federal breach reporting. The HHS Office for Civil Rights breach portal, which tracks health-data incidents affecting 500 or more individuals, has logged a steady stream of third-party and business-associate breaches in recent years, reinforcing that the AMCA-Labcorp case is a symptom of an industry-wide structural issue rather than a one-off failure specific to a single vendor.
What Wisconsin Residents Should Do Now
For the 16,615 Wisconsin residents identified in this breach, the settlement itself does not automatically trigger a direct payout to individuals; it funds state enforcement and mandates corporate reforms rather than a consumer restitution fund. Anyone who received a data breach notification tied to Labcorp or AMCA in 2019, or who used Labcorp testing services during the exposure window of August 2018 through March 2019, should treat Social Security number and payment card exposure as an ongoing risk and monitor accounts accordingly.
Federal resources remain available for anyone affected by this or similar breaches. The Federal Trade Commission’s data breach guidance outlines consumer steps for monitoring credit and disputing fraudulent charges, while IdentityTheft.gov provides a direct reporting and recovery pathway for identity theft tied to a specific breach. Residents who suspect fraud stemming from stolen medical or financial data can also file a report with the FBI’s Internet Crime Complaint Center.
Predictions: What Comes Next
- Expect other state coalitions to reference the Labcorp reform package, particularly the mandatory CISO-level oversight and third-party assessor requirements, as a baseline template in future healthcare vendor-breach settlements.
- Quest Diagnostics’ exposure through the same AMCA breach makes it a plausible candidate for a similar multistate action if state attorneys general choose to pursue parity across companies hit by the identical vendor failure.
- Healthcare and lab companies are likely to accelerate vendor consolidation and in-house collections capabilities to reduce the number of third parties handling protected health information, directly responding to the liability exposure this case demonstrates.
- Contractual cybersecurity mandates, including required SOC 2 Type 2 audits and penetration testing for vendors, are likely to become standard boilerplate in healthcare billing and collections contracts industry-wide following this precedent.
- Given the multi-year gap between the 2019 breach and the 2026 settlement, additional state-level actions or civil suits tied to the same underlying AMCA incident remain possible as individual state investigations conclude on their own timelines.
The Bigger Picture for Vendor Risk Management
What separates this case from a typical breach-notification penalty is the emphasis on structural change over financial punishment. Regulators explicitly chose to force Labcorp into building permanent oversight infrastructure, a CISO-level security program, a vendor risk team, contractual audit rights, rather than simply extracting a larger fine and moving on. That approach reflects a broader shift across data-protection enforcement, one that increasingly treats third-party and supply-chain risk as the primary attack surface companies need to manage, a theme that has also shaped recent enforcement and disclosure trends following incidents like the record-setting downtime costs tied to ransomware and other supply-chain-driven attacks tracked throughout 2026.
For a healthcare sector that has spent years treating vendor management as a procurement function rather than a security function, the Labcorp settlement is a clear signal that regulators now expect the two to be the same thing.
Frequently Asked Questions
What is the Wisconsin-Labcorp data breach settlement about?
It’s a 44-state settlement, led by the New York Attorney General’s office, resolving investigations into how Labcorp handled a 2019 data breach at its debt collection vendor, American Medical Collection Agency (AMCA). Labcorp will pay approximately $2,287,455 across participating states and implement new vendor security requirements.
How many Wisconsin residents were affected by the Labcorp breach?
Wisconsin outlets reported 16,615 state residents were affected, part of a nationwide total of more than 27.5 million people whose information was potentially exposed in the original AMCA breach.
What data was exposed in the 2019 AMCA breach?
According to the New York Attorney General’s office, the exposed information included Social Security numbers, payment card information, and the names of medical tests and diagnostic codes associated with each patient.
Is Quest Diagnostics part of this settlement?
No. Quest Diagnostics also used AMCA and was affected by the same underlying 2019 breach, but the September 2026 multistate settlement covers Labcorp specifically, not a joint action with Quest.
Will Wisconsin residents receive individual payments from the settlement?
The settlement funds go to participating state governments rather than a direct consumer restitution fund, based on the terms described in the New York Attorney General’s announcement. Affected residents should instead rely on standard identity-monitoring and fraud-reporting resources such as IdentityTheft.gov.
What security changes is Labcorp required to make?
Labcorp must strengthen its information security program, build a vendor-focused incident response plan, minimize data sharing with debt collectors, expand its vendor risk management program, require contractual cybersecurity standards and audits from vendors, and hire an independent third-party assessor to review compliance.
Why did it take until 2026 to settle a 2019 breach?
Regulators first settled directly with AMCA in 2021, but that $21 million judgment was suspended due to AMCA’s bankruptcy. Investigators then spent additional years building the case against Labcorp itself over its vendor oversight practices, which is what resulted in the 2026 settlement.
Which states are part of the Labcorp settlement?
The coalition includes 43 states plus the District of Columbia, led by New York, and includes Wisconsin along with states such as Illinois, Michigan, Ohio, Texas, and Massachusetts, according to the New York Attorney General’s official announcement.
