Clinical Pathology Laboratories, Inc. (CPL) notified California regulators of a data security incident involving its third-party vendor, Retrieval Masters Creditors Bureau (d/b/a American Medical Collection Agency or AMCA). On May 15, 2019, CPL was informed that AMCA experienced unauthorized access to a database containing patient information. The breach affected patient data including names, addresses, phone numbers, dates of birth, service dates, balances, and treatment provider information. CPL stopped using AMCA for collection efforts and engaged cybersecurity experts. No misuse of information was known at the time of notification.