Alaska Settled With Labcorp Over 2019 Data Breach

Alaska is part of a 44-state coalition that secured a settlement regarding a major medical data security failure.

Updated on Sept. 29, 2026 in Cybersecurity

Isometric editorial illustration of a metallic data connector featuring an embossed geometric shield, symbolizing medical data security and regulatory oversight.
Alaska and a coalition of 44 states secured a $2.29 million settlement with Labcorp following a 2019 medical data security breach. AI Illustration. Upload story photo >

Live Poll

Should corporations be held legally liable for data breaches caused by their third-party vendors?

Alaska and 43 other states have reached a $2,287,455 settlement with Labcorp following a 2019 data breach at the American Medical Collection Agency. The incident exposed the personal information of 10.2 million Labcorp patients, including 82,958 residents in Alaska.

Why it matters

The settlement addresses Labcorp failure to properly oversee the security of sensitive patient data shared with third-party vendors. It mandates stricter vendor risk management and new incident response protocols to protect patient privacy moving forward.

The settlement requires Labcorp to pay $26,010 to Alaska out of the total $2,287,455 multistate fund. The breach originally impacted 10.2 million Labcorp patients out of 27.5 million total individuals affected by the AMCA incident.

The players

Labcorp

Labcorp is a global life sciences company that provides vital diagnostic information to help doctors and patients make clear decisions.

American Medical Collection Agency

This organization is a debt collection firm that serves various healthcare clients across the United States.

Cori Mills

Cori Mills serves as the Acting Attorney General for the state of Alaska.

The details

Labcorp transferred patient information to the American Medical Collection Agency for debt collection before the breach occurred. The agreement requires the company to engage a third-party assessor for information security and minimize the volume of data shared with future vendors.

Timeline

  1. The data breach occurred in 2019.

  2. A multistate coalition previously reached a settlement with the American Medical Collection Agency in 2021.

  3. Acting Attorney General Cori Mills announced the Labcorp settlement on September 29, 2026.

The Tech Race

This settlement follows the pattern set by the 2021 multistate coalition settlement with the American Medical Collection Agency, marking a continued legal focus on third-party medical data oversight. It forces companies to shift away from legacy vendor data-sharing practices toward more restrictive and secure management systems.

Residents impacted by the breach now have the assurance of new security protocols designed to minimize the sharing of their medical information with third-party vendors. These measures aim to reduce the likelihood of future data leaks involving sensitive healthcare billing records.

The takeaway

Healthcare providers and their vendors are increasingly held accountable for the security of patient data handled by third parties. Consumers should remain vigilant about monitoring their medical billing statements and credit reports for suspicious activity following any large-scale data breach.

Further reading

For more information on data protection standards in the state, visit Cybersecurity.

Source note: This article includes information reported by Alaska Native News.

Live Poll

Should corporations be held legally liable for data breaches caused by their third-party vendors?