+ Relocation assistance
More locations: Milwaukee, WI, USA
Relocation assistance is available for qualified candidates.
Labcorp provides end-to-end R&D services for life sciences and agricultural clients, including crop protection, with testing and regulatory support. It runs physicochemical analyses, safety assessments, and inhalation toxicology studies using specialized labs to evaluate inhaled substances. It differentiates itself with a global footprint and an integrated set of services across the product lifecycle, including regulatory submissions. Its goal is to help clients bring safe, effective products to market efficiently by applying rigorous science and scalable testing.
Company Size
10,001+
Company Stage
IPO
Headquarters
Burlington, Vermont
Founded
1976
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
401(k) Retirement Plan
Unlimited Paid Time Off
Tuition Reimbursement
Employee Stock Purchase Plan
LabCorp pays states $2.2M in settlement over AMCA hack. 42 States, DC Require Lab to Strengthen Security, Vendor Risk Management Practices Marianne Kolbasuk McGee (HealthInfoSec) - September 25, 2026 LabCorp has agreed to pay $2.2 million and improve its data security and vendor risk management practices - especially with debt collectors - to resolve multistate litigation stemming from a 2019 hack on American Medical Collections Agency. The hack affected more than 10.2 million patients of the medical testing lab, and the settlement announced on Thursday resolves a list of claims against North Carolina-based LabCorp involving a variety of state consumer protection and personal information protection laws, as well violations of federal laws, including HIPAA. Under the HITECH Act of 2009, state attorneys general were granted the right to pursue federal HIPAA violations. Retrieval-Masters Creditors Bureau, a then-42-year-old New York business operating under the name American Medical Collection Agency, or AMCA, filed for bankruptcy just weeks after discovering the breach in 2019 and ultimately went out of business. Besides LabCorp, the AMCA hack affected dozens of the firm's other clients and about 27.5 million people nationwide. "Companies entrusted with consumers' sensitive health and personal information remain responsible for protecting that information when they share it with outside vendors," said Jennifer Davenport, attorney general of New Jersey, where 417,308 LabCorp patients were affected by the AMCA hack. "Businesses cannot outsource their obligation to safeguard consumer data. This settlement reinforces the importance of carefully vetting vendors and maintaining strong oversight to ensure the information entrusted to them remains secure," Davenport said. Under the settlement, LabCorp will pay New Jersey $68,000. The financial settlement also will be divided in varying amounts among the other states. Besides the financial payments, LabCorp has agreed to overhaul its data security and vendor risk management practices. That includes employing a CISO - an executive or officer "with appropriate credentials, background and expertise in information security who shall be responsible for overseeing the implementation and maintenance" of the bolstered information security program, according to the settlement. LabCorp also is required to minimize the amount of data shared with vendors; expand its vendor risk management program, including establishing a dedicated team, using tools to evaluate vendors; and verify that vendors comply with security requirements. The plan also calls for LabCorp to impose additional requirements on debt-collection vendors including maintaining inventories of contracts; putting cybersecurity requirements into contracts; segmenting LabCorp data from information debt collectors hold for other clients; requiring collectors to conduct security assessments and audits; and giving LabCorp the contractual right to terminate vendors for noncompliance. "Covered entity responsibility for the actions of their business associates is a longstanding area of concern," said regulatory attorney David Holtzman, retired founder of consulting firm HITprivacy. When the HIPAA Security Rule was first enacted in 2005, it allowed covered organizations - such as medical testing labs, hospitals and clinics - "to take a hands-off approach to how their vendors and contractors handled protected health information," Holtzman said. The HITECH Act extended direct HIPAA compliance liability to business associates, but that "only goes so far," Holtzman said, who was also previously an adviser in the U.S. Department of Health and Human Services' Office for Civil Rights, which oversees federal HIPAA enforcement. "HHS can solve this problem through regulatory action to extend reasonable vendor management standards to covered entities and business associates that engage subcontractors," Holtzman added. The settlement with the state attorneys general also comes on the heels of LabCorp agreeing in June to pay $35 million to settle proposed civil class action litigation related to the AMCA incident. Under that agreement, LabCorp also said it would improve its data security practices (see: LabCorp Agrees to Pay $35M to Settle AMCA Data Breach). A coalition of 41 state attorneys general in 2021 also reached a $21 million settlement with AMCA in the incident (see: Debt Collection Firm Reaches Breach Settlement With States). AMCA first learned that the company might have a problem when it received a series of "Common Point of Purchase" notices in 2019 suggesting that a disproportionate number of credit cards that at some time had shown up on AMCA's web portal were later associated with fraudulent charges, court documents said. AMCA said it shut down its web portal to prevent any further compromises of customer data and engaged outside consultants who confirmed that AMCA's servers had been hacked as early as August 2018. LabCorp did not immediately respond to ISMG's request for comment on the settlement with the state attorneys general. The 42 states participating in the settlement are Alabama, Alaska, Arizona, Arkansas, Colorado, Connecticut, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, New York, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, Wisconsin and West Virginia - involved in the settlement - plus Washington D.C.
Attorney General James secures $2.3 million and reforms to protect consumers after Labcorp Data Breach. By Chris Boyle Published: September 24 2026 Massive Data Breach Exposed the Personal Information of Over 27.5 Million People Nationwide. New York Attorney General Letitia James today joined a bipartisan coalition of 43 other attorneys general in securing approximately $2.3 million and critical reforms to protect consumers from Laboratory Corporation of America (Labcorp) after a 2019 data breach impacted millions of Labcorp customers. The data breach affected Labcorp's debt collector, American Medical Collection Agency (AMCA), potentially exposing the personal information of over 27.5 million people nationwide, including 10.2 million Labcorp patients, 420,000 of which lived in New York. As part of a settlement with Attorney General James and the coalition, Labcorp will overhaul its data security practices and develop a new system for sharing data with third party debt collectors to protect consumers. Labcorp will also pay approximately $2.3 million to the states, including nearly $90,000 to New York. "Corporations have a responsibility to protect their customers' private data, especially sensitive medical information," said Attorney General James. "Millions of patients' private health information was potentially exposed because of Labcorp's failures to protect its customers. As a result of our investigation, Labcorp will make critical changes to protect patients and prevent this kind of data breach from happening again." AMCA is based in Elmsford, New York and specializes in small-balance medical debt collection, primarily for laboratories and medical testing facilities. Labcorp, based in Burlington, North Carolina, provides laboratory testing for diagnostic services. Between August 1, 2018 and March 30, 2019, a hacker accessed AMCA's internal system and was able to collect customers' personal information. Despite numerous warnings from banks that processed their payments about a potential breach, AMCA failed to detect the intrusion. The breach exposed the personal information - including Social Security numbers, payment card information, and names of medical tests and diagnostic codes - of approximately 420,00 New Yorkers. As a result of Attorney General James and the coalition's investigation, Labcorp must make comprehensive changes to its security policies to better protect its customers, especially when they interact with Labcorp's vendors. These changes include: * Improving Labcorp's information security program and developing an incident response plan that includes internal reporting of vendor security breaches; * Minimizing data sharing with vendors while balancing certain needs of debt collectors to meet their legal obligations; * Expanding the vendor risk management program to include requiring a dedicated team, employing tools to evaluate vendors, and verifying vendor compliance; * Implementing new requirements for debt collectors, enforcing cybersecurity standards through contracts, segmenting data which is often aggregated by debt collectors for multiple clients, requiring debt collectors to perform assessments and audits, and including the right of termination for non-compliance; and * Hiring a third-party assessor to perform an information security assessment with a focus on vendor risk management. As part of the settlement, Labcorp will pay $2,287,455 to the states, including $89,178 to New York. This settlement will supplement a multistate settlement with AMCA that Attorney General James and the coalition secured in 2021, which included a $21 million suspended payment due to the company's bankruptcy. Attorney General James is a leader in holding companies accountable for data breaches that put consumers at risk. In July 2026, Attorney General James secured $18 million from 23 and Me for failing to protect customers' genetic data. In November 2025, Attorney General James secured $1.7 million from Illuminate Education after sensitive student data was stolen in a data breach. In October 2025, Attorney General James announced her office secured $14.2 million from eight car insurance companies for failing to protect the private information of more than 825,000 New Yorkers. In March 2025, Attorney General James secured $975,000 from Root, an auto insurer, and sued Allstate for failing to protect New Yorkers' information. In January 2025, Attorney General James secured $450,000 from three companies that distributed home security video cameras for failing to secure consumers' private home security videos. Joining Attorney General James in securing this settlement are the attorneys general of Alabama, Alaska, Arizona, Arkansas, Colorado, Connecticut, Delaware, Florida, Georgia, Hawaii, Idaho, Illinois, Indiana, Iowa, Kansas, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Nebraska, Nevada, New Hampshire, New Jersey, New Mexico, North Carolina, Ohio, Oklahoma, Oregon, Pennsylvania, Rhode Island, South Carolina, Tennessee, Texas, Utah, Vermont, Virginia, Washington, Wisconsin, West Virginia, and the District of Columbia. For New York, this matter was handled by Deputy Bureau Chief Clark Russell of the Bureau of Internet and Technology, under the supervision of Bureau Chief Kim Berger. The Bureau of Internet and Technology is a part of the Division for Economic Justice, which is led by Chief Deputy Attorney General Chris D'Angelo and overseen by First Deputy Attorney General Meghan Faux.
Labcorp Holdings stock fell 3.3% on Tuesday after the Centers for Medicare & Medicaid Services announced it will cut reimbursement rates for lab work by up to 15%, effective 1 January 2027. CMS disclosed it has been paying approximately 16% more for lab work than private insurers. The agency estimates the reduced rates will save taxpayers $1 billion annually. Labcorp derives roughly 8% of its revenue from CMS reimbursement, meaning a full 15% rate reduction would decrease annual revenue by 1.2%. Successive 15% yearly reductions are possible through 2029, implying a worst-case scenario of approximately 3.6% revenue reduction. In its latest SEC filing, Labcorp identified Medicare and Medicaid rate reductions as a key investment risk.
Teal Health has raised $22 million in Series A funding, taking its total funding to $45 million as it prepares to expand access to at-home HPV cervical cancer screening.
Evvy has raised $40 million in an oversubscribed Series B round led by Catalio Capital to expand its vaginal microbiome platform into reproductive healthcare, focusing on fertility and IVF. The round included U.S. Fertility's Innovation Fund, Labcorp Venture Fund, and existing investors including General Catalyst and Left Lane Capital, bringing total funding to nearly $60 million. The company has served over 100,000 patients and partnered with 3,000 healthcare practitioners, building what it describes as the world's largest proprietary dataset on the vaginal microbiome. Ninety-six percent of patients contribute data anonymously to clinical research. Evvy's at-home Vaginal Health Test analyses over 700 bacteria and fungi using metagenomic sequencing, priced at $159 per test. The funding will scale EvvyAI, the company's data and AI platform underlying its diagnostic services. CEO Priyanka Jain aims to make vaginal microbiome screening routine preventive care, comparable to Pap smears, addressing areas where women's health research has historically been limited.