How One Small Billing Company Breached 20 Million Patients at Once
Quest Diagnostics and LabCorp are two of the biggest lab testing companies in the country. Neither one was hacked directly — their billing vendor was. Here's why that's the pattern to watch for.
In 2019, patients of two of the largest lab testing companies in the US — Quest Diagnostics and LabCorp — started receiving breach notifications. Neither company had been hacked. A billing collections vendor almost nobody had heard of had been.
What American Medical Collection Agency actually did
AMCA was a debt-collection company that handled unpaid medical bills on behalf of labs, hospitals, and other healthcare providers. To do that job, it needed patients’ names, dates of birth, addresses, balances — and in many cases, the more sensitive detail of what lab test or provider the bill was for.
Why two unrelated companies got breached at once
Attackers accessed AMCA’s own payment page over an eight-month period. Because AMCA processed collections for dozens of healthcare organizations, that single point of failure fanned out into breach notifications from Quest Diagnostics (around 11.9 million patients), LabCorp (around 7.7 million), and several smaller clients — over 20 million people combined, none of whom had a direct account with AMCA at all.
The pattern this illustrates
This is the same shape as the later MOVEit and Blackbaud incidents: a vendor most patients never chose and never heard of holds data on behalf of an organization they do trust, and a single breach at that vendor becomes breach notifications from multiple unrelated brands simultaneously. AMCA itself filed for bankruptcy within months of the disclosure, unable to survive the fallout.
What to actually do about it
- A notification from a company you don’t recognize referencing a lab test or provider you do recognize is a legitimate letter, not automatically a phishing attempt — verify by calling the provider directly using a number you look up independently, but don’t dismiss it as spam without checking.
- Billing and collections data is still sensitive even without a full medical record attached — knowing what lab test someone had, combined with their name and address, is enough detail to make follow-up phishing attempts convincing.
- This is a good moment to ask your own healthcare providers what third parties handle your billing — you’re generally not able to opt out, but knowing the vendor landscape helps you recognize a legitimate future notification when one arrives.
Worried this affects you?
Check whether your email address has shown up in this breach — or any other — in seconds.
Run a free breach check →Related coverage
The MOVEit Breach Explained: What Actually Happened
A 2023 flaw in a file-transfer tool used by thousands of companies led to one of the largest data breaches in recent memory. Here's what it means if you got a notification letter.
The Change Healthcare Breach: The Largest Healthcare Hack in US History
A ransomware attack on a single billing company froze prescriptions and payments across the entire US healthcare system for weeks. Here's what happened and who was affected.