Courthouse exterior with stone columns and American flag flying in front
Photo via Unsplash

TL;DR: On June 12, 2026, LabCorp agreed to a $35 million class action settlement to resolve litigation over the 2019 American Medical Collection Agency (AMCA) data breach [1]. The breach exposed the personal and financial data of 7.7 million LabCorp patients, plus 11.9 million Quest Diagnostics patients, between August 2018 and March 2019 [2][3]. AMCA, the company that actually got hacked, filed for bankruptcy in June 2020 and its estate has no money left to pay claims [4]. The LabCorp settlement, announced seven years after the breach, is largely an insurance-funded payment. After attorneys\u2019 fees, the average class member will see less than five dollars. HHS Office for Civil Rights has not announced a fine against LabCorp for the breach, which is the pattern, not the exception.

The Settlement

The agreement was filed on June 12, 2026 in the U.S. District Court for the District of New Jersey, the same court that has been managing the multidistrict litigation (MDL 2904) since 2019 [1][5]. Judge Brian R. Martinotti, who has overseen the case for most of its life, signed off on the preliminary settlement. The settlement class is every U.S. resident whose personal information was exposed in the AMCA breach and whose information was maintained by LabCorp.

The headline number is $35 million. That money flows into a common fund, out of which come: (1) attorneys\u2019 fees, typically 25 to 33 percent of a class action common fund, (2) administrative costs, (3) service awards to the named plaintiffs, and (4) whatever cash and credit-monitoring benefits actually reach the 7.7 million class members. The settlement also includes identity-theft insurance and three years of credit monitoring for class members who enroll.

There is no admission of liability from LabCorp. The company has consistently argued that the breach occurred at AMCA, a third-party vendor, and that LabCorp itself had no direct role in the failure. That argument did not stop the case, because LabCorp, as the HIPAA covered entity, was named as the defendant in the consolidated complaint, not AMCA (which by 2020 was bankrupt and no longer a viable defendant) [5].

What Happened at AMCA

AMCA was a New Jersey-based medical debt collection agency. It sent bills and processed payments on behalf of clinical laboratories, including LabCorp, Quest Diagnostics, BioReference Laboratories, and several smaller regional labs. Its business model was simple: AMCA received lab orders, billed patients or their insurers, and operated the web payment portal where patients entered credit card and bank account information to pay their bills.

That web payment portal was the entry point. Between August 1, 2018 and March 30, 2019, an unauthorized actor had access to AMCA\u2019s systems, including the patient payment pages [2][3]. The data exposed for each affected patient typically included:

  • Full name
  • Date of birth
  • Social Security number (for credit-balance refund payments)
  • Address
  • Phone number
  • Credit card number and expiration date (for patients who paid through the portal)
  • Bank account number and routing number (for patients who paid by ACH)
  • The name of the ordering provider, the date of service, and in some cases the specific tests performed

The medical data in the leak is what made the AMCA breach worse than a typical payment processor breach. A credit card you can cancel. A bank account you can close. But the test you had done in October 2018, the diagnosis code attached to it, the fact that the ordering physician was a fertility specialist or a genetic counselor, that information is permanent and not cancelable. Patients received letters from LabCorp and Quest in June 2019 warning them of the exposure, including, in some cases, the specific lab tests they had taken [2][3].

AMCA discovered the breach on May 14, 2019, after its payment processor (First Data, now Fiserv) flagged anomalous payment activity. AMCA notified LabCorp on May 24, 2019 and Quest Diagnostics on June 3, 2019. LabCorp sent out its notification letters starting June 4, 2019. Quest sent out its notifications the same day. The two companies together accounted for 19.6 million of the estimated 20+ million patients whose data AMCA had handled during the breach window [2][3].

Seven Years of Litigation

The first class action complaints were filed within days of the June 2019 notifications. By August 2019, the Judicial Panel on Multidistrict Litigation had consolidated the cases into MDL 2904, sitting in the District of New Jersey [5]. Judge Brian R. Martinotti was assigned to the case. AMCA itself was named as a defendant. LabCorp and Quest Diagnostics were also named.

The legal theory against LabCorp and Quest was straightforward. Under HIPAA, the laboratories were covered entities. AMCA was their business associate. The breach was, in the language of the complaints, the foreseeable result of failing to vet AMCA\u2019s security practices, failing to require adequate safeguards in the business associate agreement, and failing to monitor AMCA\u2019s compliance with the agreement. Plaintiffs pointed to industry guidance dating back to 2016 warning that payment-portal vendors handling protected health information needed multi-factor authentication, network segmentation, and continuous monitoring. AMCA had none of these [6].

The litigation did not move quickly. AMCA filed for Chapter 11 bankruptcy protection in June 2020, after the breach drove its largest customers (LabCorp and Quest) to terminate the relationship and the cost of breach notifications and credit monitoring exhausted its cash [4]. The bankruptcy stayed the case against AMCA itself. The case against LabCorp and Quest continued.

Discovery dragged on. Plaintiffs sought AMCA\u2019s internal security assessments, the contracts between AMCA and the laboratories, the breach forensics reports from AMCA\u2019s incident response vendor (Mandiant), and the internal communications between AMCA and the laboratories in the days after the breach was discovered. Defense counsel pushed back on scope. Judge Martinotti entered a series of case management orders, including a 2022 order compelling production of the Mandiant report over AMCA\u2019s objections, and a 2023 order certifying the class [5].

Quest Diagnostics reached its own settlement in 2024. The Quest settlement figure is not publicly disclosed in the same form as the LabCorp deal; court records and the class notice described the Quest resolution as a combination of additional credit monitoring, identity-restoration services, and a small cash component for documented out-of-pocket losses. The 11.9 million Quest patients did not get a $35 million common fund [7].

LabCorp fought on. The case went through two rounds of mediation in 2024 and 2025, both of which failed. A third mediation session in early 2026 produced the $35 million framework announced on June 12 [1][5]. The agreement is preliminary; class members will receive a notice, have the right to object or opt out, and a final approval hearing is scheduled for fall 2026.

The $35 Million Math

Run the division: $35 million divided by 7.7 million class members equals $4.55 per patient. That is the gross per-patient figure before attorneys\u2019 fees, administrative costs, and the named-plaintiff service awards are subtracted.

Subtract a typical class action common-fund fee of 30 percent, which is what the plaintiffs\u2019 bar will almost certainly request, and the net distributable fund is closer to $24.5 million. Subtract the administrative costs of mailing 7.7 million notices, running a claims portal, and processing claims, and the working fund is closer to $22 million. Subtract service awards to the named plaintiffs (typically $5,000 to $25,000 each, with a class of this size there are likely 20 to 40 named plaintiffs), and the working fund is in the $21 to $22 million range.

That is the money actually available to compensate the 7.7 million people whose Social Security numbers, lab tests, dates of birth, and bank account numbers were exposed.

The catch: class actions in data breach cases rarely see claim rates above 10 percent, and the average rate is closer to 5 percent. A 5 percent claim rate on 7.7 million class members is 385,000 claims. $22 million divided by 385,000 claims is $57 per claim. A 10 percent claim rate is 770,000 claims and $28 per claim. Class members with documented out-of-pocket losses (the cost of credit monitoring they already bought, the cost of an identity-theft investigation, the cost of replacing a bank account that saw fraudulent ACH activity) can claim more, but the documentation requirements are tight and the cap on out-of-pocket loss claims is typically $250 per claimant [8].

The settlement also includes three years of credit monitoring, identity-theft insurance (typically $1 million in coverage), and a hotline for identity-restoration services. These are the same credit monitoring services that LabCorp and Quest were already offering in 2019, so the marginal benefit of an additional three years of credit monitoring is the main non-cash recovery for class members who enroll.

The math gets worse when you consider the seven-year wait. A dollar in 2026 is worth less than a dollar in 2019, and the value of credit-monitoring services and identity-theft insurance has not kept pace with the rise in identity-fraud costs. The Federal Trade Commission logged 5.7 million identity-theft and fraud reports in 2024, up from 4.8 million in 2023, with $12.5 billion in total reported losses [9].

Who Actually Pays

LabCorp is required to fund the $35 million settlement, but a substantial portion of that money will come from LabCorp\u2019s cyber-insurance policy. The exact split is not public. Industry benchmarks for healthcare cyber-insurance policies written in 2018-2019 (the year the AMCA breach occurred) put policy limits in the $25 million to $50 million range, with retentions in the $1 million to $5 million range. For a $35 million settlement, the realistic split is that LabCorp\u2019s insurer pays $25 million to $30 million and LabCorp covers the rest out of cash on hand.

This is the structural story of the AMCA settlement, and it is the structural story of every major healthcare breach class action settlement in the last five years. The covered entity pays a small deductible. The insurance carrier pays the rest. Class members see a fraction of the headline number. The covered entity reports the settlement in a regulatory filing (in LabCorp\u2019s case, an 8-K and a 10-Q note) and treats the incident as closed.

The insurer, meanwhile, pays out the claim, recalculates the covered entity\u2019s premium at renewal, and either raises the rate, lowers the coverage limit, or excludes certain categories of vendor breach from the policy. The 2024 renewal cycle was brutal for the entire healthcare industry: premiums rose 20 to 40 percent year-over-year for hospitals and labs, and several large carriers stopped writing new business in the sector. LabCorp\u2019s premiums went up too, but the dollar figure is buried in a footnote [10].

The Federal Enforcement Gap

HHS Office for Civil Rights (OCR) opened a compliance review of LabCorp in June 2019, immediately after the breach notification. The review focused on whether LabCorp had conducted an adequate security risk analysis of AMCA before sharing patient data with the vendor, whether the business associate agreement satisfied HIPAA\u2019s requirements, and whether LabCorp\u2019s monitoring of AMCA was sufficient.

As of June 2026, OCR has not announced a fine or a settlement with LabCorp related to the AMCA breach [11]. This is consistent with OCR\u2019s track record on healthcare breach enforcement. The agency has the authority to levy civil monetary penalties of up to $1.5 million per violation category per year, and a single breach can be split into dozens of violation categories. The actual fines, when they are levied, are almost always smaller than the maximum and almost always smaller than the cost of the underlying breach.

The historical record makes the pattern clear. Anthem paid $16 million in 2020 to settle OCR charges over the 2015 breach that hit 78.8 million patients, an average of $0.20 per patient. Excellus Health Plan paid $5.1 million in 2021 for a 2015 breach affecting 9.3 million patients, an average of $0.55 per patient. Memorial Hermann paid $2.4 million in 2017 for a 2011 breach affecting 402 patients, an average of $5,970 per patient, which is the closest OCR has come to a meaningful per-patient penalty and remains an outlier [11].

For a 7.7 million patient breach, even a maximum-tier OCR fine would be rounding error compared to the $35 million class action settlement. And the $35 million class action settlement, as we have shown above, is itself rounding error after attorneys\u2019 fees. The cumulative financial consequence for LabCorp of an event that exposed 7.7 million people\u2019s Social Security numbers, dates of birth, bank account numbers, and medical test histories is, in order of magnitude, $0 to $30 million out of an annual revenue base of more than $13 billion.

That is the federal enforcement gap. The penalties are set by statute at levels that made sense for a 1996 Congress thinking about 1996-scale breaches, and the penalties have not been adjusted for the scale of the modern healthcare data economy. The result is that the only real money that ever moves in a major healthcare breach case is the insurance money, and the only people who actually pay the cost are the patients, who pay it in the form of higher insurance premiums, higher lab fees, and seven years of credit-monitoring enrollment.

What Class Members Should Do

The settlement administrator will mail notices to class members whose current address is on file with LabCorp or AMCA. Class members who have moved since 2019 may not receive a notice; the settlement website, once live, will have a name-and-address lookup tool. The deadline to file a claim, object, or opt out will be approximately 90 days after the notice mailing, which puts the operative deadline in late fall 2026. The final approval hearing is scheduled for a date in November or December 2026.

For class members who want to claim cash, the documentation requirements depend on the tier of claim. Tier 1: ordinary class membership, no documentation required, eligible for a pro-rata cash payment and the credit monitoring services. Tier 2: documented out-of-pocket losses (credit monitoring purchases, identity-theft investigation costs, account-replacement fees, late fees or bounced-check fees tied to the breach), eligible for reimbursement up to a cap of $250 per claimant. Tier 3: documented identity theft or fraud directly traceable to the breach, eligible for reimbursement of the full documented loss with a higher cap. The settlement administrator has not yet published the exact claim form, but the structure is standard for data-breach class actions [8].

The credit-monitoring and identity-theft insurance benefits are automatic for class members who enroll. Enrolling does not waive any future right to sue for newly discovered harm tied to the breach, although the settlement does release LabCorp, Quest, and AMCA\u2019s bankruptcy estate from most claims arising from the breach itself. If a class member\u2019s data shows up in a future breach, identity-fraud scheme, or targeted attack, and that class member can show the AMCA breach was a contributing cause, the release of claims is broad enough to cover most of the foreseeable harm.

For class members who want to opt out and pursue their own lawsuit, the opt-out deadline is the same as the claim deadline. Opting out preserves the right to sue LabCorp individually, but individual data-breach lawsuits against deep-pocketed corporate defendants rarely settle for more than the class action settlement amount, and almost always take longer. The opt-out is the right move only for class members with specific and documented damages that exceed the class action cap, which is rare for a breach of this vintage.

What This Means

Seven years. $35 million. 7.7 million people. $4.55 per person, gross, before attorneys\u2019 fees, before administrative costs, before the named-plaintiff service awards, before the seven-year inflation adjustment, before the seven years of credit monitoring the labs were already offering.

The LabCorp-AMCA settlement is the second major healthcare data-breach class action to close in the last 30 days, following the Change Healthcare / UnitedHealth resolution announced in May 2026. The two cases share a structural shape: a business associate or vendor gets breached, the covered entity pays the settlement, the insurance carrier writes the check, the patients receive a fraction of the headline number, and HHS OCR announces no fine.

The pattern is the story. AMCA is bankrupt, the breach at AMCA was technically foreseeable, the business associate agreement between AMCA and the laboratories was technically compliant with the minimum HIPAA requirements, and the minimum HIPAA requirements are now two decades behind the threat model. The 2026 settlement does not change any of that. It closes the books on the 2019 breach and the 2019 regulatory regime that was supposed to prevent it. The next breach will be against the 2026 regime, and the 2026 regime is, structurally, the same as the 2019 regime, with slightly higher insurance premiums.

Until HHS OCR fines are set at a level that makes healthcare boards take security risk seriously, and until business-associate agreements require real technical safeguards (multi-factor authentication on payment portals, network segmentation, continuous monitoring, third-party security audits), the AMCA breach will keep happening. It will just be at a different vendor, in a different state, with a different covered entity on the hook for the insurance payment.

Sources

  1. HIPAA Journal: Labcorp Agrees to $35M Settlement to Resolve AMCA Data Breach Litigation (June 12, 2026)
  2. HIPAA Journal: Quest Diagnostics Announces 11.9 Million Patients Affected by AMCA Data Breach (June 2019)
  3. HIPAA Journal: LabCorp Data Breach Affects 7.7 Million Patients (June 2019)
  4. HIPAA Journal: American Medical Collection Agency Files for Bankruptcy (June 2020)
  5. CourtListener / RECAP: In re American Medical Collection Agency, Inc., MDL No. 2904 (D.N.J.) docket
  6. HHS.gov: HIPAA Security Rule (45 CFR Part 160 and Subparts A and C of Part 164)
  7. HIPAA Journal: Quest Diagnostics Resolves AMCA Data Breach Litigation (2024)
  8. ClassAction.org: LabCorp AMCA Data Breach Class Action Settlement background
  9. Federal Trade Commission: Consumer Sentinel Network Data Book 2024 (identity theft and fraud reports)
  10. HIPAA Journal: Healthcare Cybersecurity Insurance Premiums Surge 20-40% in 2024
  11. HHS.gov: HIPAA Resolution Agreements and Civil Monetary Penalties (OCR enforcement record)