2019 LabCorp (AMCA collections vendor) — ~7.7M consumers; billing-channel payment data subset
Data compromised
Names, DOB, addresses, phones, service dates, balances, and—where consumers paid via AMCA—financial payment artifacts per SEC-adjacent patient notifications
Technical writeup
Laboratory Corporation of America (LabCorp) disclosed that an intrusion at third-party collector American Medical Collection Agency (AMCA) between 1 August 2018 and 30 March 2019 exposed demographic and receivables metadata on roughly 7.7 million LabCorp-affiliated consumers, with AMCA advising that roughly 200,000 might have had payment-card or bank-account data touched when paying balances through AMCA’s payments flow. LabCorp stressed it did not transmit laboratory results or diagnostic content to AMCA in the same disclosures summarized by Krebs on Security.
Root cause
Long-running compromise of vendor-hosted patient billing/payments Web stack