- August 15, 2026
- Updated 2:17 am
Millions Eligible for Compensation in Labcorp Data Breach Settlement
- 13 Views
- admin
- August 5, 2026
- Cybersecurity Health
Millions of Americans are eligible for compensation from a $35 million class action settlement following a healthcare data breach involving Labcorp. The settlement addresses claims stemming from a cyberattack at American Medical Collection Agency (AMCA), a vendor used by Labcorp for billing and collections, which reportedly exposed sensitive personal and medical data of millions of patients. Eligible consumers must submit claims by September 3.
Why This Matters
Labcorp ranks among the largest diagnostic testing companies globally, performing over 750 million tests annually and serving patients both nationally and internationally. Healthcare data breaches are increasingly prevalent, with medical records often storing sensitive information like Social Security numbers, insurance details, and payment information.
The breach potentially endangered data of around 7.7 million Labcorp patients. This exposure opens the door to identity theft and fraud risks. The settlement provides affected individuals with cash compensation and free monitoring services.
Lawsuit Allegations
The lawsuit claims Labcorp did not adequately secure patient information transmitted to AMCA, also known as Retrieval-Masters Creditors Bureau Inc., for billing purposes. Court documents reveal AMCA experienced a cybersecurity breach affecting systems housing personal and health-related data.
Alex Beene, a financial literacy instructor at the University of Tennessee at Martin, noted the breach extends beyond initial incidents, as stolen medical and personal data can lead to identity theft and medical identity fraud years afterward.
Plaintiffs argued affected consumers faced increased risks of identity theft and fraud due to the breach. Labcorp denies wrongdoing but agreed to the $35 million settlement to resolve claims. This settlement does not imply misconduct or law violations but rather resolves disputed claims, according to the settlement website.
Labcorp Usage
Labcorp is among the leading global laboratory service providers, employing roughly 71,000 individuals and operating nearly 2,200 patient service centers in the U.S. Worldwide, Labcorp conducts over 750 million tests annually. Thus, the settlement impacts numerous Americans who have undergone diagnostic testing.
According to Beene, healthcare organizations and their vendors are becoming major targets for cybercrime, pressing them to provide significant financial compensation for affected individuals.
Eligibility and Deadlines
People might be eligible if Labcorp transmitted their personal data to AMCA and their information existed within systems affected by the cybersecurity incident between August 2018 and March 2019. The deadline for claims is September 3. Late submissions may be ineligible for compensation.
Filing a Claim
Eligible consumers can submit claims on the official settlement website. Options include:
- Claiming documented out-of-pocket expenses related to the breach
- Requesting alternative cash payment if no documented losses were incurred
If you received notification your data was involved in the AMCA breach or had a Labcorp account managed by AMCA during the affected period, check your eligibility before the September deadline. Many consumers discard breach notices and forget older cybersecurity incidents, leaving settlements like this frequently unclaimed.
Compensation Details
Class members can select compensation options, though the cash amount fluctuates based on the number of valid claims. Payments generally follow court approval and resolution of appeals, which could take months before consumers receive compensation.
Looking Ahead
Consumers need to mark September 3 as crucial for filing a claim. Following submission, the settlement administrator will review and decide eligible payouts. Within the healthcare industry, reliance on external billing and tech providers might enhance risks of exposing sensitive patient information during cyberattacks.