Hawaii Settled Labcorp Data Breach Investigation
The settlement follows a 2019 vendor breach that compromised the personal information of 10.2 million patients.
Updated on Oct. 4, 2026 in Cybersecurity

Live Poll
Should large companies be held legally responsible for data breaches caused by their third-party vendors?
The Hawaii Department of Commerce and Consumer Affairs has settled an investigation into Labcorp regarding a 2019 data breach at vendor AMCA. The breach exposed the personal data of 10.2 million Labcorp patients nationwide, including 17,347 residents in Hawaii.
Why it matters
The settlement addresses failures in vendor oversight and mandates that Labcorp implement a rigorous information security program. It reflects a growing regulatory focus on holding corporations accountable for the security practices of their third-party service providers.
The settlement requires Labcorp to implement a new information security program and perform third-party vendor risk management assessments. This follows a broader incident where 27.5 million total individuals were impacted by the 2019 AMCA breach.
The players
Labcorp
A global life sciences company providing diagnostic testing and drug development services.
Hawaii Department of Commerce and Consumer Affairs
The state agency responsible for consumer protection and business regulation in Hawaii.
The details
The breach occurred when American Medical Collection Agency (AMCA), a third-party vendor, failed to secure sensitive data. Labcorp is now required to formalize an incident response plan to mitigate future exposure. The company must also hire an external assessor to evaluate and audit their internal vendor risk management processes.
Timeline
2019: The data breach occurred at AMCA.
2021: The multistate coalition reached a settlement with AMCA.
October 4, 2026: The Hawaii Department announced the Labcorp settlement.
The Tech Race
This settlement highlights a persistent gap in third-party vendor oversight within the healthcare sector. It follows a pattern established by enforcement actions under the HIPAA Security Rule where liability increasingly shifts toward the data controller.
Residents in Hawaii who were among the 17,347 affected patients are part of a broader group receiving oversight protections under the new security mandate. While the financial settlement has been finalized, impacted individuals should remain vigilant for follow-up communications regarding their data security status.
The takeaway
The Labcorp case underscores the ongoing risk of vendor-side vulnerabilities in large-scale medical record storage. Readers should monitor future filings for updates on Labcorp's compliance with the newly mandated third-party security assessment audits.
Further reading
For more on how state regulators monitor institutional data practices, visit Cybersecurity.
Source note: This article includes information reported by Maui Now | Hawaii News | Local Maui News and Information | Hawaii News.
Live Poll
Should large companies be held legally responsible for data breaches caused by their third-party vendors?







