LABORATORY CORPORATION OF AMERICA HOLDINGS
ent_019e0d84921cc71abbbba40f1526e2ba
Disclosures
14
HHS OCR · State AG · Leak Site · 11 jurisdictions
Multi-filing incidents
3
incidents joining 2+ filings here
Max affected reported
10,251,784
nationwide · HHS OCR NC
Leak-site claims
1
unverified actor claims
Identity resolution
- Canonical name
- LABORATORY CORPORATION OF AMERICA HOLDINGS
- Normalized
- laboratory corporation of america— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- OZ7UA8IXAIFILY2VZH07
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- labcorp.com
- Corporate parent
- LABCORP HOLDINGS INC.— per SEC Exhibit 21 filing
Disclosure history (14)newest first
- NORTH CAROLINAHHS OCRas victim2023-09-08
LabCorp reported to HHS on 2023-09-08 an unauthorized access/disclosure affecting 1,431 individuals. An employee impermissibly disclosed PHI—including names, dates of birth, addresses, lab results, and treatment information—to wrong recipients via paper/films. The CE notified HHS, affected individuals, and media, and provided credit monitoring and implemented additional safeguards.
- Montana State AGas victim2023-09-08
Labcorp inadvertently faxed patient lab results, names, DOBs, addresses, and medical record numbers to incorrect recipients between July 9-11, 2023. Discovered July 10, 2023. Labcorp notified the unintended recipient, requested destruction of data, and offered one year of Experian IdentityWorks. No financial or SSN data was involved.
- Massachusetts State AGas victim2019-07-17
Laboratory Corporation of America Holdings reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-07-17. 750 Massachusetts residents were affected. The report records the breach type as electronic.
- Oregon State AGas victim2019-07-17
Laboratory Corporation of America Holdings (LabCorp) reported a data breach to the Oregon Attorney General. The breach was reported on 2019-07-17. The breach occurred during 8/1/2018 - 3/30/2019. The breach was discovered on 5/14/2019. Notice was sent on 7/13/2019.
- New Hampshire State AGas victim2019-07-16
LabCorp notified NH AG of a breach involving its vendor AMCA. Unauthorized access occurred Aug 2018–Mar 2019. LabCorp learned of the incident on May 14, 2019. 303 NH residents affected. Data included names, addresses, DOBs, SSNs, and health/financial info. Notices sent July 13, 2019.
- South Carolina State AGas victim2019-07-15
Laboratory Corporation of America Holdings (LabCorp) notified South Carolina residents that its third-party vendor, American Medical Collection Agency (AMCA), experienced unauthorized access to its web payment system between August 1, 2018, and March 30, 2019. LabCorp's own systems were not affected. The breach potentially exposed patient names, addresses, balances, dates of birth, referring physicians, dates of service, health insurance information, and Social Security Numbers. LabCorp stopped using AMCA immediately upon notification and offered two years of Experian IdentityWorks to affected individuals.
- California State AGas victim2019-07-15
LabCorp notified California residents that its vendor, American Medical Collection Agency (AMCA), experienced unauthorized access to its web payment page between August 1, 2018, and March 30, 2019. LabCorp was informed on May 14, 2019. Affected data may include names, addresses, phone numbers, dates of birth, referring physicians, dates of service, health insurance information, and potentially Social Security Numbers. LabCorp stopped using AMCA and offered two years of identity monitoring.
- NORTH CAROLINAHHS OCRas victim2019-07-13
Laboratory Corporation of America Holdings dba LabCorp reported to HHS on 2019-07-13 a Hacking/IT Incident affecting 10,251,784 individuals. The breach involved its business associate, Retrieval-Masters Creditors Bureau, Inc. (AMCA), which suffered a cyber-attack exposing patient PHI (names, SSNs, health info) stored on network servers. LabCorp notified HHS, individuals, and media, and terminated its relationship with AMCA.
- Washington State AGas reporting2019-07-13
LabCorp reported a third-party breach involving vendor American Medical Collection Agency (AMCA). Unauthorized access occurred from Aug 1, 2018 to Mar 30, 2019. LabCorp was notified on May 14, 2019. 18,330 Washington residents affected. Data included names, DOB, SSNs, and health info. Notices sent July 13, 2019.
- Montana State AGas victim2019-07-13
LabCorp notified Montana AG of a third-party breach involving its vendor, American Medical Collection Agency (AMCA). AMCA experienced unauthorized access to its web payment page between August 1, 2018, and March 30, 2019. LabCorp was informed on May 14, 2019. Affected data included patient names, addresses, DOBs, SSNs (potentially), and health insurance info. LabCorp's systems were not directly affected.
- Illinois State AGas victim2019-01-01
LABORATORY CORPORATION OF AMERICA HOLDINGS (LABCORP) filed a data-breach notice with the Illinois Attorney General during 2019 (case 2019-264). The register records the breach as discovered on August 1, 2018. Additional entities named: AMERICAN MEDICAL COLLECTION AGENCY. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- GLOBALLeak Siteas victim2018-07-14
- NORTH CAROLINAHHS OCRas victim2013-05-01
Laboratory Corporation of America (LabCorp) reported to HHS on 2013-05-01 a Theft affecting 1,580 individuals. A desktop computer tagged for destruction was stolen after hours from a LabCorp facility. The computer contained ePHI including diagnoses, names, Social Security numbers, and dates of birth. LabCorp notified HHS, affected individuals, and law enforcement, initiated an internal investigation, retrained employees, changed device storage locations, and updated desktop encryption.
- ARIZONAHHS OCRas victim2010-04-01
Laboratory Corporation of America reported to HHS on 2010-04-01 a theft affecting 2773 individuals. An external hard drive containing electronic protected health information was stolen. The breached information included names, medical record numbers, dates of birth, lab test data, and some Social Security numbers. In response, the company has initiated a project to encrypt external hard drives and other media.
Supply-chain cascadesreviewed and confirmed
- LABORATORY CORPORATION OF AMERICA HOLDINGS’s filing is one of at least 17 in the Retrieval-Masters Creditors Bureau, Inc supply-chain incident (2019).