Labcorp Has Settled Data Breach Claims for $2.2 Million
The laboratory testing firm reached an agreement with 40 states following a 2019 security incident.
Updated on Sept. 24, 2026 in Cybersecurity

Live Poll
Should companies be held strictly liable for data breaches that occur through their third-party vendors?
Labcorp has agreed to pay $2.2 million to 40 states to resolve investigations into a 2019 data breach that exposed the personal information of 10 million individuals. The company has also finalized a separate $35 million class action settlement related to the same event.
Why it matters
The settlement highlights the growing legal and financial accountability companies face for failing to protect sensitive patient data. It also underscores the increased regulatory scrutiny on how corporations manage security standards when working with third-party vendors.
The 2019 breach impacted 400,000 residents in New Jersey and 200,000 in Pennsylvania. As part of the resolution, Labcorp will minimize data shared with vendors and implement stricter cybersecurity requirements for debt collection agencies.
The players
Labcorp
Labcorp is a global life sciences company that provides vital information to help doctors, hospitals, and pharmaceutical companies make clear decisions.
The details
Beyond the state-level agreement, the company has agreed to pay $35 million to satisfy a separate class action settlement. New Jersey will receive $68,000 from the state settlement, while Pennsylvania is slated to receive $43,000.
Timeline
The data breach occurred in 2019.
The settlement agreement was announced on September 24, 2026.
The Tech Race
This settlement follows a pattern established by HIPAA Security Rule enforcement actions that hold healthcare entities responsible for third-party security vulnerabilities. It reflects a broader shift toward tighter regulatory control over the data lifecycle in the healthcare sector.
While the settlement provides some legal resolution, individuals affected by the breach should monitor their credit reports for signs of identity theft. Consumers may also see enhanced data verification procedures when interacting with debt collection services used by medical providers.
The takeaway
Companies are increasingly forced to tighten security protocols and limit data sharing with third-party vendors to avoid future legal liabilities. Consumers should remain vigilant about their personal information whenever interacting with large-scale medical laboratory services.
Further reading
For more on evolving threats, see the latest updates in Cybersecurity.
Live Poll
Should companies be held strictly liable for data breaches that occur through their third-party vendors?










