44 State AGs Settle With Labcorp Over 2019 AMCA Data Breach
Independently fact-checked against primary sources (last audited September 25, 2026). · 7 primary sources cited on this page. How we verify our legal content

Forty-four state attorneys general announced a settlement on September 24, 2026 with Laboratory Corporation of America Holdings over the 2019 American Medical Collection Agency breach. Labcorp will pay $2,287,455 to the states and rebuild how it vets the vendors that handle patient data.
Information last verified on September 25, 2026. This is a developing story; we update it as the record changes.
Status: Entered. This is a multistate attorney general enforcement settlement, signed as an Assurance of Voluntary Compliance and announced on September 24, 2026, with an effective date of October 1, 2026. The $2,287,455 is paid to the participating states, not to consumers. It creates no consumer claim, no claim form and no individual payout.
Jurisdiction scope: Forty-four jurisdictions signed, including the District of Columbia. Connecticut, Florida, Illinois, Indiana, Michigan and Texas led the investigation, with an executive committee of Maryland, Massachusetts, New York, North Carolina and Tennessee. Seven states did not sign: California, Louisiana, Mississippi, Montana, North Dakota, South Dakota and Wyoming. Forty-three states plus the District of Columbia makes the 44 signatories. The settlement binds Labcorp nationally as a matter of its own compliance program, but only signatory attorneys general released claims and only they can enforce it.
What Happened
American Medical Collection Agency was the trade name of Retrieval-Masters Creditors Bureau, a debt collector that chased unpaid medical bills for laboratories and hospitals. Labcorp first contracted with AMCA in 1996, according to the settlement document, and sent it patient billing data for collection.
AMCA told Labcorp that an unauthorized user appeared to have had access to AMCA's systems between August 1, 2018 and March 30, 2019, according to Labcorp's SEC filings. AMCA notified Labcorp of the incident on May 14, 2019, according to Labcorp's SEC filings, and Labcorp publicly announced the breach on June 4, 2019, the date the settlement document uses. The Connecticut Attorney General's office puts the nationwide exposure at more than 27.5 million individuals across all of AMCA's clients, including 10.2 million Labcorp patients. Connecticut counted 43,666 affected residents, Pennsylvania roughly 218,408, and Delaware 115,250.
AMCA itself filed for bankruptcy. The multistate coalition settled with AMCA in 2021, after that bankruptcy petition was dismissed, for a payment that was suspended because the company could not pay it. That left the question the states have now answered against Labcorp: what does the company that handed over the data owe when its contractor is the one that gets breached?
The document signed here is an Assurance of Voluntary Compliance, the instrument state attorneys general use to close a consumer protection investigation without filing suit. Connecticut signed on September 11, 2026 and Labcorp on September 18, 2026. It became effective October 1, 2026, and Connecticut's $81,296 share is due within 30 days of that date, or within 30 days of final approval where state law requires a court to approve the agreement. Delaware's allocation is $30,135 and Pennsylvania's is $43,313, which gives a sense of how the total is split by resident count rather than evenly.
Labcorp does not concede anything. Paragraph 35 states that nothing in the agreement is "an admission or concession or evidence of any liability or wrongdoing whatsoever," and that it is entered "for settlement purposes only."
What Labcorp Agreed to Do
The money is the small part. The operative section runs 20 paragraphs of injunctive relief, paragraphs 4 through 23, and nearly all of it is about controlling contractors.
Program and people. Within 120 days of the effective date, and annually after that, Labcorp must review and update its information security program. It must employ a chief information security officer with real credentials who advises the CEO and the board on security posture and risk. Security awareness and privacy training must reach everyone whose job touches patient personal information or protected health information within 180 days, then annually, and new hires within 30 days.
Incident response and internal escalation. The security program must include an incident response plan that specifically covers the handling, investigation and reporting of what the agreement calls a Vendor Security Event, defined as a compromise at a vendor affecting the data of at least 500 Labcorp consumers. Labcorp must have a process for escalating those events to senior management or the board. The agreement is careful to add that this internal process does not substitute for the company's legal notification duties.
Sharing less data. Labcorp must limit what it discloses to vendors to the minimum necessary for the purpose, and must write policies specific to debt collectors. Two are concrete: a process to give a debt collector only the additional information needed when a consumer disputes a debt and asks for verification, and a process requiring debt collectors to confirm in writing each year that they have deleted or destroyed consumer data once a debt is satisfied or the referral is withdrawn.
Vendor risk management. Labcorp must maintain a written vendor risk management program, review it at least annually, and staff a dedicated vendor risk management team with security, risk or audit experience that reports to the CISO at least quarterly. Vendor assessments must be scaled to a documented risk rating, and where Labcorp uses security questionnaires it must corroborate the answers rather than filing them.
Debt collector contract terms. This is the most prescriptive part. Labcorp must keep an inventory of its debt collector contracts recording what data each one holds and when it was last assessed. By contract, each debt collector must adopt a recognized cybersecurity framework such as the NIST Cybersecurity Framework, segment Labcorp data from other data in shared environments, dispose of data to NIST standards, protect cryptographic keys properly, and remediate critical vulnerabilities flagged by US-CERT. Each must run annual risk assessments and annual penetration tests and provide attestations. Each must undergo an annual SOC 2 Type 2 audit, a bi-annual HITRUST CSF validated assessment, or a reasonable equivalent. Contracts must spell out who notifies consumers after a vendor breach, and Labcorp must retain the right to act against a non-compliant collector up to terminating the contract. Existing contracts must be amended to include these terms within 12 months.
Independent verification. Within 18 months, Labcorp must obtain an assessment from an independent third-party assessor holding a CISSP or equivalent certification with at least five years of experience evaluating vendor risk management. The assessor reports to the Connecticut Attorney General within 60 days of completing the work, and other signatory states can request a copy. Connecticut will treat the report as exempt from public records disclosure.
Paragraph 30 sets the clock: the obligations in paragraphs 9 through 22, which is most of the vendor and debt collector machinery, expire five years after the effective date.
What the Law Actually Says
The spine of this case is a principle worth stating plainly: handing data to a contractor does not hand off responsibility for it.
The attorneys general built that on three stacked bodies of law, listed in Appendix A of the agreement state by state. First, each state's unfair and deceptive acts and practices statute, from the Connecticut Unfair Trade Practices Act at Conn. Gen. Stat. 42-110b to the Texas Deceptive Trade Practices Consumer Protection Act at Tex. Bus. & Com. Code 17.41 through 17.63. Second, each state's breach notification or personal information protection act, such as the Illinois Personal Information Protection Act at 815 ILCS 530/1 or the Florida Information Protection Act at Fla. Stat. 501.171. Those statutes impose duties both to safeguard personal information and to notify residents when it is compromised, and they are the everyday backbone of US data privacy laws at the state level. Coverage and thresholds differ enough between states that the practical picture only emerges from a state-by-state privacy law comparison.
Third, and most important to the vendor theory, HIPAA. Labcorp is a covered entity. AMCA, as a debt collector processing patient billing data on its behalf, was a business associate as that term is defined at 45 CFR 160.103. Under 45 CFR 164.308(b)(1), a covered entity may let a business associate handle electronic protected health information "only if the covered entity obtains satisfactory assurances, in accordance with 164.314(a), that the business associate will appropriately safeguard the information." The parallel privacy rule provision at 45 CFR 164.502(e)(2) requires those assurances to be "documented through a written contract or other written agreement or arrangement." The minimum necessary standard at 45 CFR 164.502(b) and 164.514(d) limits how much protected health information can be sent in the first place.
Read together, those provisions are why the agreement reads the way it does. A business associate agreement is not a formality that shifts the risk downstream. It is the covered entity's own compliance obligation, and the states treated a thin one as a failure by Labcorp rather than only by AMCA. The breach notification duty runs the same direction: the covered entity generally owes notice to affected individuals, which is the mechanism explained in our guide to how HIPAA breach reporting works.
The agreement also borrows definitions from debt collection law. "Debt Collector" tracks the Fair Debt Collection Practices Act definition at 15 U.S.C. 1692a(6), and the debt verification process Labcorp must build references the CFPB's Regulation F at 12 CFR 1006.34.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
Divide $2,287,455 by 10.2 million affected Labcorp patients and you get about twenty-two cents a person. Read as a penalty, that number is not a deterrent. It should not be read as a penalty. This settlement is best understood as a compliance decree that happens to carry a modest check, and the interesting question is whether the decree changes behavior at the companies that were not sued.
Two features suggest it might. The debt collector requirements in paragraphs 17 through 22 are unusually specific for a state attorney general settlement. Naming SOC 2 Type 2 and HITRUST, requiring data segmentation in multi-tenant environments, requiring key management hygiene and US-CERT remediation timelines: these are the terms a security team would write, not the terms a lawyer would. Once a document like that is public, it becomes the yardstick other attorneys general use in the next vendor breach, and general counsel at other health systems now have a published list of what regulators consider reasonable. That is how a small settlement does large work.
The other feature is the twelve-month contract amendment deadline. Labcorp has to reopen every existing debt collector contract and add these terms. Debt collectors that serve multiple laboratories will be asked for the same terms by one large client, and it is cheaper to standardize than to maintain two security postures. The obligations flow downhill whether or not the collectors were investigated.
The limits are real too. The obligations sunset after five years. The third-party assessor's report goes to the Connecticut Attorney General under a confidentiality expectation rather than to the public, so nobody outside the coalition will be able to check the work. There is no admission of liability, no finding of fact, and no adjudication of whether Labcorp's original vendor oversight actually violated anything. And the seven non-participating states released nothing, which is a detail worth watching.
The broader pattern is the one to take away. The AMCA breach potentially exposed the data of more than 27.5 million people through a company almost none of them had heard of, because their laboratories and hospitals sent their data there. Vendor risk is now the dominant shape of healthcare data exposure, and enforcement is following it upstream to whoever chose the vendor.
How This Affects You
Start with what this settlement does not do. If your data was in the AMCA breach, this September 2026 settlement pays you nothing. There is no claim form to fill out, no portal, no eligibility questionnaire and no deadline to meet. Any website that offers to file a claim for you against this $2.3 million settlement is not describing a real process. State attorneys general sue on behalf of the state, and the money they recover goes to the state treasury or to consumer protection enforcement funds.
The consumer compensation path is separate, and it runs through a different court. The 23 putative class actions filed against Labcorp over the AMCA Incident were consolidated into a multidistrict litigation in the U.S. District Court for the District of New Jersey, as Labcorp's own quarterly report to the Securities and Exchange Commission records. That filing states that "[o]n March 2, 2026, the parties entered into a Class Action Settlement and Release, which is subject to court approval." Labcorp discloses no settlement amount in that filing, but the attorneys general do. The Connecticut and Delaware releases both state that "Labcorp has agreed to a $35,000,000 settlement in the related class action lawsuit, which is still ongoing with other AMCA client covered entities." The court record supplies what the releases leave out. The deadline to submit a claim in that settlement was September 3, 2026, and on August 20, 2026 the court entered a Final Approval Order and Judgment as to the Labcorp track. Kroll Settlement Administration LLC is the court-appointed administrator, at amcadatabreachsettlement.com. Anyone who filed before the deadline should check there for payment timing. The phrase the attorneys general use, "still ongoing with other AMCA client covered entities," refers to the rest of the multidistrict litigation, which continues against other defendants, not to the Labcorp settlement.
If you were affected and did not file, the practical options now are protective rather than compensatory, and none of them cost money. A credit freeze at each of the three nationwide credit bureaus is free by federal law, stops new accounts from being opened in your name, and can be lifted temporarily when you need credit. Medical identity theft is the specific risk in a breach like this one, so it is worth reading the explanation of benefits statements your insurer sends and questioning any service you did not receive. Our step-by-step walkthrough of what to do after a data breach covers the sequence in more detail.
For settlements that are actually open to claims right now, our class action settlement tracker lists current claim windows and official administrator links. Nothing here is advice about your particular situation, and we cannot tell you whether any specific claim of yours is viable.
Disclaimer: This article is general legal information about a public enforcement settlement, not legal advice, and reading it does not create an attorney-client relationship. Settlement terms, deadlines and court schedules change. Verify anything you plan to act on against the official source documents or consult a licensed attorney in your state.
Related articles
- What to do after a data breach, step by step
- Reporting HIPAA breaches: requirements, timelines and process
- US data privacy laws hub
- Open class action settlement tracker
- State privacy law comparison and tracker
Last updated: 2026-09-25. This is a developing story; details verified as of 2026-09-25.
Frequently Asked Questions
Do I get money from this settlement?
No. The $2,287,455 Labcorp agreed to pay under the September 2026 settlement goes to the 44 participating state attorneys general, not to consumers. There is no claim form, no eligibility check and no individual payout from this settlement. The agreement does not call the payment a penalty; it lets each attorney general apply the state's share to costs of investigation and litigation, attorneys' fees, or a consumer protection enforcement fund. Nothing is distributed to residents.
Is there any settlement that did pay Labcorp patients?
Yes, and it is now closed to new claims. The class actions against Labcorp over the AMCA Incident were consolidated into a multidistrict litigation in the U.S. District Court for the District of New Jersey, In re American Medical Collection Agency, Inc., Customer Data Security Breach Litigation, No. 2:19-md-02904. The Connecticut and Delaware attorneys general both state that Labcorp 'has agreed to a $35,000,000 settlement in the related class action lawsuit, which is still ongoing with other AMCA client covered entities', and Labcorp told the Securities and Exchange Commission that on March 2, 2026 the parties entered into a Class Action Settlement and Release that is subject to court approval. The court record supplies the rest: Labcorp funded a $35,000,000 non-reversionary common fund, the court appointed Kroll Settlement Administration LLC as settlement administrator, the deadline to submit a claim was September 3, 2026, and on August 20, 2026 the court entered a Final Approval Order and Judgment as to the Labcorp track. If you filed before that deadline, contact the administrator about payment timing. If you did not file, the window has closed. The multidistrict litigation continues as to other AMCA client covered entities, whose separate settlement received preliminary approval on August 20, 2026 with a final approval hearing set for January 7, 2027.
Who was affected by the AMCA breach?
According to the Connecticut Attorney General, the intrusion at American Medical Collection Agency potentially exposed the personal information of more than 27.5 million people nationwide across all of AMCA's clients, including 10.2 million Labcorp patients. The settlement agreement describes the incident as occurring at AMCA and being publicly reported in June 2019.
Why was Labcorp held responsible when AMCA was the company that got breached?
Because a covered entity's duty to safeguard patient data does not transfer to its contractor. Under 45 CFR 164.308(b)(1) a HIPAA covered entity may only let a business associate handle electronic protected health information if it obtains documented satisfactory assurances that the information will be safeguarded. The states also invoked each state's consumer protection and breach notification statutes. AMCA itself went through bankruptcy, and the coalition's 2021 settlement with AMCA was suspended because the company could not pay.
Which states are part of this settlement?
Forty-four jurisdictions signed, including the District of Columbia. Connecticut, Florida, Illinois, Indiana, Michigan and Texas served as lead states, with an executive committee of Maryland, Massachusetts, New York, North Carolina and Tennessee. The full signatory list appears in the opening paragraph of the Assurance of Voluntary Compliance.
What is an Assurance of Voluntary Compliance?
It is the instrument state attorneys general use to resolve a consumer protection investigation without filing a lawsuit. The company agrees to specific future conduct and usually a payment, the attorney general releases the claims covered by the investigation, and the agreement remains enforceable by the attorney general. In some states it must be filed with or approved by a court. This one expressly states that it is not an admission of liability.
How long do Labcorp's new security obligations last?
Paragraph 30 provides that the obligations in paragraphs 9 through 22, which include the vendor risk management program and the debt collector contract requirements, expire five years after the October 1, 2026 effective date. Some other provisions, such as the ban on misrepresenting its data protection practices and the independent assessment requirement, are structured separately.
What should I do now if my data was in the AMCA breach?
General protective steps apply to anyone in a breach of this kind. A credit freeze at each of the three nationwide credit bureaus is free under federal law and blocks new accounts opened in your name. Reviewing explanation of benefits statements from your health insurer helps catch medical identity theft. This is general information, not advice about your situation.
Updates
Updated October 1, 2026: the Labcorp Assurance of Voluntary Compliance reached its October 1, 2026 effective date; wording changed to past tense.
Independently fact-checked against the cited primary sources
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Connecticut General Statutes, Title 42 (Business, Selling, Trading and Collection Practices), Chapter 735a
§ 42-110bUnfair trade practices prohibited. Legislative intent.In forcecited in 5 of our articles
(a) No person shall engage in unfair methods of competition and unfair or deceptive acts or practices in the conduct of any trade or commerce. (b) It is the intent of the legislature that in construing subsection (a) of this section, the commissioner and the courts of this state shall be guided by interpretations given by the Federal Trade Commission and the federal courts to Section 5(a)(1) of the Federal Trade Commission Act (15 USC 45(a)(1)), as from time to time amended. (c) The commissioner may, in accordance with chapter 54, establish by regulation acts, practices or methods which shall be deemed to be unfair or deceptive in violation of subsection (a) of this section. Such regulations shall not be inconsistent with the rules, regulations and decisions of the federal trade commission and the federal courts in interpreting the provisions of the Federal Trade Commission Act. (d) It is the intention of the legislature that this chapter be remedial and be so construed.
Official text (excerpt) · last checked 2026-07-29 · Read the full text in our law library · Verify at cga.ct.gov
Cited in 1,209 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- Willow Springs Condominium Ass'n v. Seventh BRT Development Corp. (Supreme Court of Connecticut 1998, 245 Conn. 1)“…tes § 42-110a (4). The entire act is remedial in character; General Statutes § 42-110b (d); Hinchliffe v. American Motors C…”
- Hinchliffe v. American Motors Corp. (Supreme Court of Connecticut 1981, 184 Conn. 607)“…ehicle had “full-time four-wheel drive” was deceptive under General Statutes § 42-110b (a). With respect to the other CUTPA…”
- Jackson v. R. G. Whipple, Inc. (Supreme Court of Connecticut 1993, 225 Conn. 705)“…s’ actions in removing and selling her mobile home violated General Statutes § 42-110b (a) of the Connecticut Unfair Trade Pra…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: What Is the CTDPA? Connecticut Data Privacy Act Explained, Connecticut Scam and Fraud Laws: Where to Report and CUTPA (2026), Connecticut Data Privacy Laws: CTDPA Consumer Rights Guide (2026)
Florida Statutes
§ 501.171Security of confidential personal information.In forcecited in 7 of our articles
(1) DEFINITIONS.—As used in this section, the term:(a) “Breach of security” or “breach” means unauthorized access of data in electronic form containing personal information. Good faith access of personal information by an employee or agent of the covered entity does not constitute a breach of security, provided that the information is not used for a purpose unrelated to the business or subject to further unauthorized use. (b) “Covered entity” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that acquires, maintains, stores, or uses personal information. For purposes of the notice requirements in subsections (3)-(6), the term includes a governmental entity. (c) “Customer records” means any material, regardless of the physical form, on which personal information is recorded or preserved by any means, including, but not limited to, written or spoken words, graphically depicted, printed, or electromagnetically transmitted that are provided by an individual in this state to a covered entity for the purpose of purchasing or leasing a product or obtaining a service.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Data Privacy Laws: Digital Bill of Rights & Breach Rules (2026), Florida Data Breach Notification Laws: Reporting Rules & Timelines (2026), Florida Biometric Privacy Laws: Collection, Consent & Penalties (2026)
Code of Federal Regulations Title 12
§ 1006.34Notice for validation of debts.In force
(a) Validation information required —(1) In general. Except as provided in paragraph (a)(2) of this section, a debt collector must provide a consumer with the validation information required by paragraph (c) of this section either: (i) By sending the consumer a validation notice in the manner required by § 1006.42: (A) In the initial communication, as defined in paragraph (b)(2) of this section; or (B) Within five days of that initial communication; or (ii) By providing the validation information orally in the initial communication. (2) Exception. A debt collector who otherwise would be required to send a validation notice pursuant to paragraph (a)(1)(i)(B) of this section is not required to do so if the consumer has paid the debt prior to the time that paragraph (a)(1)(i)(B) of this section would require the validation notice to be sent. (b) Definitions. For purposes of this section: (1) Clear and conspicuous means readily understandable. In the case of written and electronic disclosures, the location and type size also must be readily noticeable and legible to consumers, although no minimum type size is mandated.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 24 court opinions in our collectionLatest citing opinion in our collection: 2025
Opinions citing this section in our collection:
- Aargon Agency, Inc. v. Sandy O'Laughlin (Court of Appeals for the Ninth Circuit 2023, 70 F.4th 1224)“…on” or “[w]ithin five days of th[e] initial communication.” 12 C.F.R. § 1006.34(a) (2021). Regulation F defines…”
- Randy Hopkins v. Collecto Inc (Court of Appeals for the Third Circuit 2021, 994 F.3d 117)“…since the itemization date. 84 Fed. Reg. at 23404 (proposed 12 C.F.R. § 1006.34(c)(2)(ix)); 86 Fed. Reg. at 5803–06. An…”
- CABRERA (District Court, D. New Jersey 2025)“…(2) violations of 15 U.S.C. § 1681s-2(a), (3) violations of 12 C.F.R. § 1006.34, (4) violations of 15 U.S.C. § 1692e,…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Code of Federal Regulations Title 45
§ 160.103Definitions.In forcecited in 16 of our articles
Except as otherwise provided, the following definitions apply to this subchapter: Act means the Social Security Act. Administrative simplification provision means any requirement or prohibition established by: (1) 42 U.S.C. 1320d-1320d-4, 1320d-7, 1320d-8, and 1320d-9; (2) Section 264 of Pub. L. 104-191; (3) Sections 13400-13424 of Public Law 111-5; or (4) This subchapter. ALJ means Administrative Law Judge. ANSI stands for the American National Standards Institute. Business associate: (1) Except as provided in paragraph (4) of this definition, business associate means, with respect to a covered entity, a person who: (i) On behalf of such covered entity or of an organized health care arrangement (as defined in this section) in which the covered entity participates, but other than in the capacity of a member of the workforce of such covered entity or arrangement, creates, receives, maintains, or transmits protected health information for a function or activity regulated by this subchapter, including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, patient safety activities listed at 42 CFR 3.20, billing,…
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at ecfr.gov
Cited in 374 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Courts apply the Section 160.103 definitions inside and outside HIPAA. Zani v. Rite Aid Headquarters Corp. (2017) used its health care definition to hold pharmacy flu shot calls fell within the TCPA health care exemption. Kenneth Wilson v. UnitedHealthcare Insurance Co (2022) applied its individually identifiable health information test.
Opinions citing this section in our collection:
- Northwestern Memorial Hospital v. John Ashcroft, Attorney General of the United States (Court of Appeals for the Seventh Circuit 2004, 362 F.3d 923)“…mation” as “individually identifiable health information.” 45 C.F.R. § 160.103 . Both Congress and HHS define “individ…”
- Florida Ex Rel. Attorney General v. United States Department of Health & Human Services (Court of Appeals for the Eleventh Circuit 2011, 648 F.3d 1235)“…is paid for health care in the normal course of business.” 45 C.F.R. § 160.103. And in 2009, Congress expanded HIPAA’s…”
- Zani v. Rite Aid Headquarters Corp. (District Court, S.D. New York 2017, 246 F. Supp. 3d 835)✓Rite Aid sent a prerecorded flu shot reminder to a pharmacy customer's cell phone. Reading the TCPA health care exemption against 160.103, the court held the call conveyed a health care message made on behalf of a covered entity, and granted Rite Aid summary judgment.
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Does a Failed Drug Test Show Up on Your Record?, When Is a Business Associate Agreement Required? (2026), South Dakota Data Breach Notification Laws: Reporting Rules & Timelines (2026)
§ 164.308Administrative safeguards.In forcecited in 4 of our articles
(a) A covered entity or business associate must, in accordance with § 164.306: (1)(i) Standard: Security management process. Implement policies and procedures to prevent, detect, contain, and correct security violations. (ii) Implementation specifications: (A) Risk analysis (Required). Conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity or business associate. (B) Risk management (Required). Implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level to comply with § 164.306(a). (C) Sanction policy (Required). Apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity or business associate. (D) Information system activity review (Required). Implement procedures to regularly review records of information system activity, such as audit logs, access reports, and security incident tracking reports. (2) Standard: Assigned security responsibility.
Official text (excerpt) · last checked 2026-09-16 · Read the full text in our law library · Verify at ecfr.gov
Cited in 12 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- United States Ex Rel. Sheldon v. Kettering Health Network (Court of Appeals for the Sixth Circuit 2016, 816 F.3d 399)“…ity risk analysis in accordance with the requirements under 45 C.F.R. § 164.308(a)(1) and implement security updates as…”
- Florida Ex Rel. Attorney General v. United States Department of Health & Human Services (Court of Appeals for the Eleventh Circuit 2011, 648 F.3d 1235)“…nd technical privacy safeguards and employee training. See 45 C.F.R. §§ 164.308, 164.310, 164.312. Fourth, Congr…”
- Weinberg v. Advanced Data Processing, Inc. (District Court, S.D. Florida 2015, 147 F. Supp. 3d 1359)“…contain, and correct security violations in violation of 45 C.F.R. § 164.308 (a)(1); Failing to identify and respo…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Washington Medical Records Retention Laws (2026 Guide), HIPAA Compliance Companies: Top Platforms Compared (2026), HIPAA Compliant Texting Apps: Secure Messaging for Healthcare (2026)
§ 164.502Uses and disclosures of protected health information: General rules.In forcecited in 16 of our articles
(a) Standard. A covered entity or business associate may not use or disclose protected health information, except as permitted or required by this subpart or by subpart C of part 160 of this subchapter. (1) Covered entities: Permitted uses and disclosures. A covered entity is permitted to use or disclose protected health information as follows: (i) To the individual; (ii) For treatment, payment, or health care operations, as permitted by and in compliance with § 164.506; (iii) Incident to a use or disclosure otherwise permitted or required by this subpart, provided that the covered entity has complied with the applicable requirements of §§ 164.502(b), 164.514(d), and 164.530(c) with respect to such otherwise permitted or required use or disclosure; (iv) Except for uses and disclosures prohibited under § 164.502(a)(5)(i), pursuant to and in compliance with a valid authorization under § 164.508; (v) Pursuant to an agreement under, or as otherwise permitted by, § 164.510; and (vi) As permitted by and in compliance with any of the following: (A) This section. (B) Section 164.512 and, where applicable, § 164.509. (C) Section 164.514(e), (f), or (g).
Official text (excerpt) · last checked 2026-09-16 · Read the full text in our law library · Verify at ecfr.gov
Cited in 290 court opinions in our collectionLatest citing opinion in our collection: 2026
In the courts (editorial summary, independently checked):Section 164.502 is the Privacy Rule's general bar on using or disclosing protected health information. Opis Management Resources, LLC (2013) held it preempted a Florida law compelling release of deceased residents' records to a spouse or named representative; Disability Rights Texas v. Hollis (2024) applied the required-by-law exception.
Opinions citing this section in our collection:
- Northwestern Memorial Hospital v. John Ashcroft, Attorney General of the United States (Court of Appeals for the Seventh Circuit 2004, 362 F.3d 923)“…sub-part or by subpart C of part 160 of this subchapter.” 45 C.F.R. § 164.502 (a). Before looking to the various exce…”
- Opis Management Resources, LLC v. Secretary, Florida Agency for Health Care Administration (Court of Appeals for the Eleventh Circuit 2013, 713 F.3d 1291)✓Nursing homes refused to give deceased residents' records to spouses who were not personal representatives under 45 CFR 164.502(g); the Eleventh Circuit held Florida's statute compelling those blanket disclosures was preempted as an obstacle to HIPAA's privacy objectives.
- United States ex rel. Baltazar v. Warden (District Court, N.D. Illinois 2014, 302 F.R.D. 256)“…nduct was protected under HIPAA’s whistleblower exception, 45 C.F.R. § 164.502 (j)(l). 2 Regardless of whether Baltaz…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Also relied on in: Connecticut Recording Laws (2026): Hybrid Consent Rules Explained, Michigan Recording Laws (2026): Consent Rules and Participant Exception, How to Find Old Medical Records Online
United States Code Title 15
§ 1692aDefinitionsIn force
As used in this subchapter— The term “Bureau” means the Bureau of Consumer Financial Protection. The term “communication” means the conveying of information regarding a debt directly or indirectly to any person through any medium. The term “consumer” means any natural person obligated or allegedly obligated to pay any debt. The term “creditor” means any person who offers or extends credit creating a debt or to whom a debt is owed, but such term does not include any person to the extent that he receives an assignment or transfer of a debt in default solely for the purpose of facilitating collection of such debt for another. The term “debt” means any obligation or alleged obligation of a consumer to pay money arising out of a transaction in which the money, property, insurance, or services which are the subject of the transaction are primarily for personal, family, or household purposes, whether or not such obligation has been reduced to judgment.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at uscode.house.gov
Cited in 2,916 court opinions in our collectionLatest citing opinion in our collection: 2026
Opinions citing this section in our collection:
- William C. Lewis v. Acb Business Services, Inc., (96-3093/3498), American Express Travel Related Services Company, Inc. James P. Connors, (96-3498) (Court of Appeals for the Sixth Circuit 1998, 135 F.3d 389)“…its “principal purpose” is not “the collection of debts.” 15 U.S.C. § 1692a(6). Rather, Amex is primarily in the bu…”
- Henson v. Santander Consumer USA Inc. (Supreme Court of the United States 2017, 582 U.S. 79)“…tempts to collect . . . debts owed or due . . . another.” 15 U. S. C. §1692a(6). The complaint filed in this case…”
- James v. Wadas (Court of Appeals for the Tenth Circuit 2013, 724 F.3d 1312)“…debts owed or due or asserted to be owed or due another.” 15 U.S.C. § 1692a(6). In Heintz v. Jenkins, the…”
Identified automatically from the court opinions citing this section — not a ranking of which case controls.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Office of the Attorney General, State of Connecticut, “Attorney General Tong Leads Multistate Settlement with Labcorp,” press release, September 24, 2026.(portal.ct.gov).gov
- Assurance of Voluntary Compliance, In the Matter of Laboratory Corporation of America Holdings, entered into by the Attorneys General of 44 jurisdictions, signed September 11 and September 18, 2026, effective October 1, 2026 (25 pp., incl. Appendix A state statute table).(portal.ct.gov).gov
- Delaware Department of Justice, “AG Jennings announces $2.3 million multistate settlement with Labcorp over AMCA Data Breach,” September 24, 2026 (Delaware share $30,135; 115,250 Delaware residents).(news.delaware.gov).gov
- Pennsylvania Office of Attorney General, “Attorney General Sunday Announces Multistate Settlement with Labcorp over American Medical Collection Agency Data Breach,” September 24, 2026 (Pennsylvania share $43,313; approx. 218,408 residents).(attorneygeneral.gov).gov
- 45 C.F.R. § 164.308, Administrative safeguards, paragraph (b), Business associate contracts and other arrangements (U.S. Government Publishing Office, govinfo).(govinfo.gov).gov
- 45 C.F.R. § 164.502, Uses and disclosures of protected health information: General rules, paragraph (e), Disclosures to business associates (U.S. Government Publishing Office, govinfo).(govinfo.gov).gov
- Labcorp Holdings Inc., Form 10-Q for the quarterly period ended June 30, 2026, U.S. Securities and Exchange Commission (discloses the March 2, 2026 Class Action Settlement and Release subject to court approval in the District of New Jersey and the multi-state attorneys general information requests).(sec.gov).gov
- Final Approval Order and Judgment as to the Labcorp track (ECF No. 940), In re American Medical Collection Agency, Inc., Customer Data Security Breach Litigation, No. 2:19-md-02904 (D.N.J. Aug. 20, 2026); Motion for Final Approval (ECF No. 925-1) stating 'The deadline to submit a claim is September 3, 2026' and the non-reversionary $35,000,000 fund; ECF No. 941 granting preliminary approval in the other-labs track with a final approval hearing set for 7 January 2027. Docket via CourtListener/RECAP.(courtlistener.com)