Labcorp Settles With 44 States Over a Collector (09/25/2026)
- › Labcorp settled with 44 state attorneys general for about $2.29 million over the 2018 to 2019 breach at its collection agency AMCA, which affected more than 27.5 million people.
- › The settlement requires Labcorp to make its debt collectors run risk assessments, penetration tests, and annual SOC 2 Type 2 audits.
- › DOJ revised the Justice Manual on September 18 to bar treating agency guidance as binding in False Claims Act enforcement.
- › Guidance can still show knowledge, industry standards, and falsity in false certification cases, so it has not stopped mattering.
- › The 11th Circuit clarified what the government must prove about a defendant's knowledge under the Anti-Kickback Statute.
The Labcorp settlement arrived roughly seven years after the breach it resolves, and the dollar figure is the least interesting part of it. The terms describe, in unusual detail, the vendor risk program a regulator expects a healthcare company to run over the companies that handle its patients’ data. Anybody who uses a collection agency, a billing service, or a statement printer can read the obligations as a checklist of what the next settlement will ask for.
Top 5 Critical Compliance Alerts
1. Labcorp Settles With 44 States Over the AMCA Breach
A coalition of 44 state attorneys general settled with Labcorp for $2,287,455 over the breach at American Medical Collection Agency, its debt collection vendor, where an attacker was inside the network from August 1, 2018, until March 30, 2019, and took names, Social Security numbers, and financial and medical information for more than 27.5 million people, including more than 10.2 million Labcorp patients, per the HIPAA Journal. Labcorp must maintain a security program with a chief information security officer, include vendor incidents in its incident response plan, run vendor risk management with third-party assessors, and require its debt collectors to conduct risk assessments, penetration tests, and annual SOC 2 Type 2 audits. It separately settled a class action for $35 million.
Operator Note: Pull the list of vendors who hold your patient or customer data for collections, billing, and mailing, and ask each one for its latest SOC 2 Type 2 report. The ones who cannot produce one are the ones this settlement is describing.
2. DOJ Limits How Agency Guidance Can Be Used in FCA Cases
On September 18, the Department of Justice revised the Justice Manual so prosecutors may not treat agency guidance as binding or use noncompliance with guidance alone to prove a False Claims Act violation, per JD Supra. Guidance can still be used to show a party knew the law, to establish professional or industry standards, and to help prove falsity, materiality, and intent where a party falsely certified compliance. A second analysis describes the same revisions as sharpening FCA enforcement standards, per JD Supra.
Operator Note: This narrows one route to liability without closing it. If your organization certifies compliance with a standard that is technically only guidance, that certification is still the thing that can be tested.
3. The 11th Circuit Clarifies Anti-Kickback Intent
The 11th Circuit Court of Appeals clarified the government’s burden to prove what a defendant knew about the source of payments for an item or service furnished in violation of the Anti-Kickback Statute, per JD Supra. Intent elements decide most of these cases, which makes a ruling on what must be proven worth reading closely for anybody in healthcare sales or referrals.
4. SOC 2 Has Not Caught Up With AI Agents
AI agents often act through human credentials and take actions that existing SOC 2 controls cannot distinguish from a person’s, which leaves a gap the framework was not built to see, per BleepingComputer. A clean SOC 2 report from a vendor running agents on your data may not describe what those agents can do.
5. MedImpact and Rosch Visionary Systems Announce Breaches
Notification letters are going out for breaches at pharmacy benefit manager MedImpact Healthcare Systems and at Rosch Visionary Systems, per the HIPAA Journal. A pharmacy benefit manager sits between insurers, pharmacies, and patients, so its breach lands on members who may never have heard of it.
Additional Compliance Alerts
Regulatory Fines & Enforcement Actions
- Wayne Memorial Hospital and Regional Urology settle breach suits: Class actions against the Georgia hospital and the Louisiana urology practice have been resolved. HIPAA Journal
- Southern Glazer’s commits to a compliance program to resolve enforcement: Another company making a strong compliance commitment its way out of a regulatory problem. Radical Compliance
Policy & Governance Updates
- An appeals court upholds Anthropic’s supply chain risk designation: A US appeals court has upheld the designation of Anthropic as a supply chain risk. CNBC
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A leader defined by a 'bias for action,' Dusten specializes in physical security assessments that impact profitability and facility resilience.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.