Multistate coalition settles with clinical lab over 2019 vendor data breach
On September 24, a bipartisan coalition of 43 state attorneys general and the District of Columbia announced a settlement with a national clinical laboratory and diagnostic services company for $2,287,455, resolving a multistate investigation into a 2019 data breach at the company’s debt collection vendor that potentially exposed the personal information of approximately 10.2 million patients. According to the settlement, the breach occurred when an unauthorized person or persons gained access to systems maintained by the vendor, which had served as the company’s debt collector since 1996. The settlement resolved claims under state consumer protection laws, state personal information protection and security breach notification laws, and HIPAA.
Under the assurance of discontinuance, the company, which did not admit any wrongdoing, agreed to review and update its information security program within 120 days, employ a chief information security officer to oversee the program, and provide annual security awareness training to personnel with access to consumer personal information or protected health information. The agreement requires the company to develop a vendor risk management program, including a dedicated team that reports to the CISO at least quarterly and uses security assessments and monitoring tools to evaluate whether vendors are taking reasonable security measures. The company must limit the sharing of protected health information with vendors to the minimum necessary and require debt collectors to confirm annually that they have deleted consumer data after the debt is satisfied or the collection referral is rescinded. For debt collectors specifically, the company must maintain a contract inventory, contractually require adherence to industry-recognized cybersecurity standards such as the NIST Cybersecurity Framework, require annual risk assessments, annual penetration tests, and annual SOC 2 Type 2 audits or equivalent, and retain the right to terminate contracts for noncompliance. An independent third-party assessor must evaluate the company’s compliance within 18 months, and the injunctive obligations expire five years after the effective date of October 1.