RealCyberNews
Back to latest
criticalMay 14, 2019 · 4 min read

How One Small Billing Company Breached 20 Million Patients at Once

Quest Diagnostics and LabCorp are two of the biggest lab testing companies in the country. Neither one was hacked directly — their billing vendor was. Here's why that's the pattern to watch for.

By RealCyberNews Editorial Team

Share

In 2019, patients of two of the largest lab testing companies in the US — Quest Diagnostics and LabCorp — started receiving breach notifications. Neither company had been hacked. A billing collections vendor almost nobody had heard of had been.

What American Medical Collection Agency actually did

AMCA was a debt-collection company that handled unpaid medical bills on behalf of labs, hospitals, and other healthcare providers. To do that job, it needed patients’ names, dates of birth, addresses, balances — and in many cases, the more sensitive detail of what lab test or provider the bill was for.

Why two unrelated companies got breached at once

Attackers accessed AMCA’s own payment page over an eight-month period. Because AMCA processed collections for dozens of healthcare organizations, that single point of failure fanned out into breach notifications from Quest Diagnostics (around 11.9 million patients), LabCorp (around 7.7 million), and several smaller clients — over 20 million people combined, none of whom had a direct account with AMCA at all.

The pattern this illustrates

This is the same shape as the later MOVEit and Blackbaud incidents: a vendor most patients never chose and never heard of holds data on behalf of an organization they do trust, and a single breach at that vendor becomes breach notifications from multiple unrelated brands simultaneously. AMCA itself filed for bankruptcy within months of the disclosure, unable to survive the fallout.

What to actually do about it

  • A notification from a company you don’t recognize referencing a lab test or provider you do recognize is a legitimate letter, not automatically a phishing attempt — verify by calling the provider directly using a number you look up independently, but don’t dismiss it as spam without checking.
  • Billing and collections data is still sensitive even without a full medical record attached — knowing what lab test someone had, combined with their name and address, is enough detail to make follow-up phishing attempts convincing.
  • This is a good moment to ask your own healthcare providers what third parties handle your billing — you’re generally not able to opt out, but knowing the vendor landscape helps you recognize a legitimate future notification when one arrives.

Worried this affects you?

Check whether your email address has shown up in this breach — or any other — in seconds.

Run a free breach check →