Labcorp has agreed to pay $35 million to resolve a long‑running class action over a data breach at its third‑party medical debt collection vendor, American Medical Collection Agency (AMCA), with millions of affected patients now eligible for cash compensation and credit monitoring if they submit claims by early September 2026.
Labcorp’s $35M Data Breach Settlement
Laboratory Corporation of America Holdings (Labcorp), one of the largest diagnostic testing companies in the U.S., has reached a $35 million class action settlement tied to a 2018–2019 cybersecurity incident at American Medical Collection Agency (AMCA), a now‑defunct small‑balance medical debt collection firm.
Labcorp used AMCA—also known as Retrieval‑Masters Creditor’s Bureau, Inc.—to collect outstanding balances from patients. Between August 2018 and March 2019, AMCA’s systems were compromised, exposing sensitive personal and medical information for millions of individuals, including roughly 7.7 million Labcorp patients. Labcorp denies any wrongdoing but agreed to the settlement to resolve the disputed claims that it failed to adequately safeguard the data it transmitted to its vendor.
Who Is Covered and What Happened
The settlement class includes all individuals whose personal information Labcorp transmitted to AMCA and whose data resided in the AMCA systems impacted by the breach during the August 2018–March 2019 window.
According to court filings and settlement notices:
-
AMCA’s systems containing personal, financial, and health‑related information were accessed by unauthorized actors over a seven‑month period.
-
The breach affected more than 21 million individuals across AMCA’s client base, including more than 10 million Labcorp patients; approximately 7.7 million Labcorp patients are estimate to have had their information potentially compromised.
-
Exposed data may include names, dates of birth, addresses, account balances, and other medical billing details, raising risks of identity theft, medical fraud, and other misuse.
Plaintiffs alleged that Labcorp did not implement adequate safeguards or oversight over AMCA’s data security, despite its role in transmitting patient information to the collection vendor. Labcorp maintains that the settlement is not an admission of liability but a practical resolution of the litigation.
Settlement Benefits for Affected Patients
Under the terms of the $35 million settlement, class members can seek two main forms of relief: cash compensation and monitoring services.
Key elements include:
-
Out‑of‑pocket loss reimbursement up to $5,000
Eligible class members can claim up to $5,000 for documented, unreimbursed losses tied to the breach, including identity theft expenses, medical fraud, professional service costs, credit monitoring subscriptions, and up to 10 hours of time spent remedying fraud or identity theft at $25 per hour. -
Alternative cash payment (estimated around $50)
Class members who did not incur documented out‑of‑pocket losses may elect an alternative cash payment, estimated to be about $50 per claimant, though the final amount may increase or decrease depending on how many claims are filed. -
Free monitoring and insurance
The settlement also provides two years of free credit and medical information monitoring, along with identity theft insurance, offered through services such as CyEx Medical Shield Pro.
The $35 million fund will also cover attorneys’ fees and expenses, notice and administration costs, and service awards to the class representatives, with the remainder used to pay individual claims and fund monitoring services.
Key Deadlines and Claims Process
Consumers whose data was transmitted by Labcorp to AMCA and may have been affected by the breach must act within set deadlines to receive benefits.
Important dates:
-
Objection and exclusion deadline: July 27, 2026
Class members wishing to object to the settlement or opt out must do so by this date. -
Claim filing deadline: September 3, 2026
Claim forms—either for out‑of‑pocket losses or the alternative cash payment—must be submitted online or postmarked by September 3, 2026. -
Final approval hearing: August 20, 2026 (Labcorp track), with a fairness hearing noted around early September in some notices
The court will consider final approval of the settlement and related matters at a hearing scheduled for late August 2026.
Settlement payments will not be distributed until after the court grants final approval and any appeals are resolved, meaning consumers may need to wait several months after the final hearing before compensation is issued.
Affected patients can obtain detailed information, review eligibility criteria, and submit claims through the official settlement website and settlement administrator, Kroll Settlement Administration LLC.
Industry and Credit & Collection Implications
For the credit and collection industry, the Labcorp‑AMCA settlement underscores several critical trends and risks:
-
Third‑party collection vendor risk:
The breach occurred not in Labcorp’s own systems but in those of a specialized medical debt collection vendor, highlighting the growing exposure creditors face through outsourced collection and billing relationships. The case reinforces that creditors may face litigation and reputational damage when vendors mishandle consumer data, even when the creditor denies direct fault. -
Data security as a core compliance issue:
With millions of medical billing accounts affected and a sizable settlement fund dedicated to monitoring and remediation, the case illustrates how cybersecurity lapses in the collections pipeline can quickly become major consumer protection events with multi‑million‑dollar consequences. -
Consumer redress structures in data‑breach cases:
The Labcorp settlement follows a familiar class action pattern—tiered compensation for documented losses, small alternative cash payments for those without quantifiable damages, and multi‑year credit and identity monitoring. For collection agencies and creditors, this structure provides a blueprint for how courts and plaintiffs’ counsel are valuing consumer harm and remediation following breach incidents.
For readers of Credit and Collection News, the Labcorp settlement is a reminder that collection operations are not just about recovery rates and compliance with FDCPA‑style conduct standards—they now carry systemic cybersecurity and vendor‑management obligations that can translate directly into significant class‑action exposure when failures occur.





