Millions of Americans may qualify for compensation from a $35 million class action settlement concerning a significant healthcare data breach involving Labcorp. This settlement addresses claims related to a cyberattack on American Medical Collection Agency (AMCA), a third-party billing and collections vendor used by Labcorp. This attack allegedly exposed sensitive personal and medical information of millions of patients. Eligible consumers have until September 3 to submit claims.
Importance of the Case
Labcorp ranks among the largest diagnostic testing companies globally, conducting over 750 million tests each year and serving patients across the United States and internationally. Data breaches in healthcare are a growing concern, as medical records often hold sensitive details such as Social Security numbers, insurance data, and payment information. The settlement reports that approximately 7.7 million Labcorp patients had their information potentially exposed, risking identity theft and fraud. The settlement provides compensation and monitoring services to affected individuals.
Lawsuit Details
The lawsuit claims that Labcorp did not adequately protect patient data transmitted to AMCA, referred to in legal documents as Retrieval-Masters Creditors Bureau Inc., for billing and collections. AMCA faced a cybersecurity breach affecting systems with personal and health-related data. Alex Beene, a financial literacy instructor at the University of Tennessee at Martin, noted the prolonged risks, stating that the stolen information could facilitate identity theft and medical identity fraud years after the incident.
Plaintiffs argued that the breach increased the risk of identity theft and fraud for affected consumers. Labcorp denies any wrongdoing but agreed to the $35 million settlement to settle claims. The settlement explicitly states it is not an admission of fault or a violation of laws, only a resolution of disputed claims.
Labcorp’s Reach
Labcorp is one of the largest laboratory service companies worldwide, employing around 71,000 people and having approximately 2,200 patient service centers across the nation. Globally, the company handles over 750 million tests annually. Thus, many Americans who have undergone tests through their healthcare providers may be affected by the settlement.
Beene emphasized the significance, pointing out that healthcare organizations and their associated vendors are prime cybercrime targets. When breaches occur, they need to provide financial compensation to those impacted.
Eligibility and Claim Filing
Eligibility is extended to individuals whose personal information was transmitted by Labcorp to AMCA and was within AMCA’s compromised systems from August 2018 to March 2019. The deadline for claims is September 3. Late submissions may render claims ineligible for compensation.
Eligible consumers should visit the official settlement website to file claims. They can:
- Submit a claim for documented out-of-pocket expenses related to the breach.
- Request an alternative cash payment if no documented losses were incurred.
If you have been notified of your involvement in the AMCA breach or had a Labcorp account managed by AMCA during that period, it is worth confirming your eligibility before the deadline. Many consumers dispose of breach notices and neglect to claim settlements, leaving numerous entitled individuals without compensation.
Compensation Amounts and Timeline
Class members can select between cash payment options, but the exact amount depends on how many valid claims are submitted. A final court approval hearing is set for August 20. Payments are typically not disbursed until the court provides final approval and any appeals are handled. At present, a payment date is yet to be determined, so recipients might have to wait several months for compensation.
Next Steps
The critical date for consumers is September 3, the claim filing deadline. After this, the settlement administrator will evaluate claims and decide on the eligible compensation.
In the broader healthcare industry context, more companies are outsourcing billing and technology processes, which can increase the exposure risk of patient data in cyberattacks.

Understanding the Rise of AI-Powered Phishing Scams
Cyberattack on Water Systems Investigated by Federal Agencies
Cyberattacks on U.S. Water Infrastructure
Cyberattacks Highlight Vulnerability of U.S. Water Systems
Rethinking the Perception of AI Threats
Cyber Threats Target US Water Infrastructure