Hawaii Settled Labcorp Data Breach Investigation

The settlement follows a 2019 vendor breach that compromised the personal information of 10.2 million patients.

Updated on Oct. 4, 2026 in Cybersecurity

Bold flat-color editorial illustration of a shipping container, representing regulatory oversight and vendor risk management in a modern corporate landscape.
Hawaii regulators reached a settlement with Labcorp over oversight failures following a 2019 vendor data breach that impacted 10.2 million patients. AI Illustration. Upload story photo >

Live Poll

Should large companies be held legally responsible for data breaches caused by their third-party vendors?

The Hawaii Department of Commerce and Consumer Affairs has settled an investigation into Labcorp regarding a 2019 data breach at vendor AMCA. The breach exposed the personal data of 10.2 million Labcorp patients nationwide, including 17,347 residents in Hawaii.

Why it matters

The settlement addresses failures in vendor oversight and mandates that Labcorp implement a rigorous information security program. It reflects a growing regulatory focus on holding corporations accountable for the security practices of their third-party service providers.

The settlement requires Labcorp to implement a new information security program and perform third-party vendor risk management assessments. This follows a broader incident where 27.5 million total individuals were impacted by the 2019 AMCA breach.

The players

Labcorp

A global life sciences company providing diagnostic testing and drug development services.

Hawaii Department of Commerce and Consumer Affairs

The state agency responsible for consumer protection and business regulation in Hawaii.

The details

The breach occurred when American Medical Collection Agency (AMCA), a third-party vendor, failed to secure sensitive data. Labcorp is now required to formalize an incident response plan to mitigate future exposure. The company must also hire an external assessor to evaluate and audit their internal vendor risk management processes.

Timeline

  1. 2019: The data breach occurred at AMCA.

  2. 2021: The multistate coalition reached a settlement with AMCA.

  3. October 4, 2026: The Hawaii Department announced the Labcorp settlement.

The Tech Race

This settlement highlights a persistent gap in third-party vendor oversight within the healthcare sector. It follows a pattern established by enforcement actions under the HIPAA Security Rule where liability increasingly shifts toward the data controller.

Residents in Hawaii who were among the 17,347 affected patients are part of a broader group receiving oversight protections under the new security mandate. While the financial settlement has been finalized, impacted individuals should remain vigilant for follow-up communications regarding their data security status.

The takeaway

The Labcorp case underscores the ongoing risk of vendor-side vulnerabilities in large-scale medical record storage. Readers should monitor future filings for updates on Labcorp's compliance with the newly mandated third-party security assessment audits.

Further reading

For more on how state regulators monitor institutional data practices, visit Cybersecurity.

Source note: This article includes information reported by Maui Now | Hawaii News | Local Maui News and Information | Hawaii News.

Live Poll

Should large companies be held legally responsible for data breaches caused by their third-party vendors?