American Medical Collection Agency
bd_af36a8d2ef226739 · schema v1 · pii pii-v1
Full breach record for American Medical Collection Agency →Laboratory Corporation of America Holdings (LabCorp) notified South Carolina residents that its third-party vendor, American Medical Collection Agency (AMCA), experienced unauthorized access to its web payment system between August 1, 2018, and March 30, 2019. LabCorp's own systems were not affected. The breach potentially exposed patient names, addresses, balances, dates of birth, referring physicians, dates of service, health insurance information, and Social Security Numbers. LabCorp stopped using AMCA immediately upon notification and offered two years of Experian IdentityWorks to affected individuals.
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2019/LabCorp.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 15, 2019
- Raw hash
- 1bb32c190d9ec2bdcc8ea45879c138e8cd77cf4f5791e212458b41e3de45ccc8
Reporting entity
- Name
- LABORATORY CORPORATION OF AMERICA HOLDINGSnorm: laboratory corporation of america
- Domain
- labcorp.com
Victim entity
- Name
- American Medical Collection Agencynorm: american medical collection agency
Incident
- Discovered
- May 14, 2019
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Third party
- via American Medical Collection Agencyvendor
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 9 weeks(62 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.