august

AMCA, 2019

The Discovery

On February 28, 2019, analysts at Gemini Advisory, a New York firm that watches the criminal card markets for banks, noticed roughly 200,000 stolen payment cards offered for sale on a dark-web storefront. Stolen cards are a commodity, and a batch of 200,000 was notable but not extraordinary. What made the analysts look twice was the data sold alongside the cards. A meaningful share of the cards — on the order of 15 percent — came bundled with dates of birth, Social Security numbers, and physical addresses. Card data with that kind of identity attached commands a premium, because it enables not just fraudulent charges but new accounts, tax fraud, medical identity theft. Someone had stolen these cards from a place where payment details and personal identity lived side by side.

Finding where is a solved problem in the banking world. When enough compromised cards share one merchant in their purchase histories, that merchant is the leak; the technique is called common-point-of-purchase analysis, and card networks run it continuously. Gemini's analysts ran the same triangulation on the batch and converged on a website most Americans had never visited and none had chosen: the online payment portal of the American Medical Collection Agency.

The name is generic by design. AMCA was a debt collector — specifically, the debt collector to which some of the country's largest medical laboratories sent their unpaid bills. The people in that batch of 200,000 were patients who had gotten a blood test, received a bill, fallen behind on it, been passed to collections, and then gone to the portal and typed in a card number to settle the debt. Paying off the medical bill was the act that exposed them.

Gemini notified federal law enforcement. Word moved through the banks. And a small company in a suburban office north of New York City began the last four months of its existence.

The Debt Collector

Retrieval-Masters Creditors Bureau, Inc., was founded in 1977 by Russell Fuchs, who was still running it four decades later from Elmsford, New York, in Westchester County. It was a recovery agency for small consumer debts. Under its own name it chased unpaid highway tolls for E-ZPass authorities and other modest balances; under the trade name American Medical Collection Agency it built a specialty in small-balance medical debt — the $40 lab bill, the $120 copay, the residue that laboratories and physician groups found uneconomical to pursue themselves. At the end of 2018 the whole enterprise employed 113 people.

Its position in the healthcare system, though, was far larger than its headcount. Clinical laboratories run enormous volumes of low-value transactions, which makes them enormous generators of small unpaid bills, and AMCA had become a collector of choice for the biggest of them. LabCorp sent it delinquent accounts directly. Quest Diagnostics reached it through an extra link: Quest had outsourced its billing operations to Optum360, a revenue-cycle contractor that was itself part of Optum, the UnitedHealth division that appears at far greater scale in the chapter on Change Healthcare, and Optum360 in turn engaged AMCA for collections. A patient who gave a blood sample at a Quest draw station and later ignored the bill had personal data flowing two contractual hops downstream, to a company whose name appeared nowhere in the encounter.

What flowed was exactly what a collector needs and a criminal wants. To dun a debtor you must know who they are, where they live, what they owe, and to whom: names, dates of birth, addresses, phone numbers, dates of service, referring providers, balances. Some clients supplied Social Security numbers. And the portal itself added the final layer — the card and bank account details that debtors entered to pay. AMCA's systems did not hold clinical data: lab results and diagnoses stayed with the laboratories. Everything else about the patient's financial encounter with the health system sat on a payment website run by a firm of a hundred people.

Under HIPAA, this arrangement had a name and a paper trail. AMCA was a business associate — in Quest's case, a subcontractor to a business associate — bound by agreement to safeguard the data. The chapter on the Anthem espionage breach describes how regulators think about covered entities, the insurers and providers patients can actually name. The business-associate layer beneath them was governed by the same rules and almost none of the same attention. Nobody was ranking debt collectors on security. Patients could not: they had never heard of the company.

The Intrusion

The forensic account that later emerged, in regulatory filings and in the multistate investigation, was brief. AMCA's web payment portal was compromised from August 1, 2018, to March 30, 2019 — eight months of unauthorized access, spanning two calendar years, through the height of the collection season. How the attackers got in, and precisely how they harvested what they harvested, has never been publicly detailed. The company was dead before it owed anyone a fuller explanation.

What is documented is how the intrusion ended: AMCA did not find it. No internal alarm fired in those eight months, or none that anyone acted on. Detection came from the outside, from the criminal economy itself. In March 2019, after Gemini's find and the banks' triangulation, AMCA began receiving common-point-of-purchase notices — the card industry's formal way of telling a merchant that a disproportionate number of cards used on its systems were turning up in fraud. Confronted with its own customers' data circulating in the markets, the company took the portal down at the end of March, moved payment processing to a third-party vendor, and brought in outside forensic investigators.

Then came notification. On May 14, 2019, AMCA informed Quest Diagnostics and Optum360 of potential unauthorized activity on its payment page. Information arrived slowly and incompletely; Quest would complain publicly that weeks in, AMCA had still not provided detailed or complete information about what was taken and whom it touched. Other clients got their notices on their own timelines. Through the second half of May, a two-hop chain of contractors passed fragments of bad news upward toward the organizations that would eventually have to face patients, while the patients themselves knew nothing.

The Disclosures

The public learned about the AMCA breach through securities filings. On June 3, 2019, Quest Diagnostics filed an 8-K with the SEC disclosing that an unauthorized user had accessed AMCA's system and that approximately 11.9 million Quest patients may have been affected. The next day, June 4, LabCorp filed its own: about 7.7 million consumers whose data had been stored on the affected system, of whom roughly 200,000 had entered credit card or bank account details on the portal. On June 6, BioReference Laboratories, a subsidiary of OPKO Health, disclosed about 422,600 more.

The tally kept growing all summer, in fragments, as smaller clients worked out their exposure. Clinical Pathology Laboratories in Texas reported about 2.2 million patients in July. CareCentrix reported roughly half a million. Penobscot Community Health Center in Maine, pathology groups in Arizona and Texas, the genetic-testing firm Natera — by August, press tallies counted at least 21 healthcare organizations and more than 24 million people; the state attorneys general who later investigated put the figure at up to 21 million. The true number was never pinned down more precisely than "on the order of 25 million," in part because the company that held the definitive records was busy dissolving.

The disclosures set off the standard machinery of American breach response. Senator Mark Warner wrote to Quest within days demanding an account of its third-party oversight; New Jersey's senators pressed AMCA and the affected labs; state attorneys general opened investigations that would eventually span most of the country. The class actions arrived in such volume that by the end of July the federal courts consolidated them into multidistrict litigation in New Jersey.

There was also confusion over who owed 25 million people notice. HIPAA's notification duties run up the chain — the business associate tells the covered entity, the covered entity tells the patient — but the chain here had two dozen covered entities, an intermediary billing contractor, and a collector at the bottom with the only complete picture and the least capacity to act on it. In practice the burden split along the data. AMCA itself mailed notices to the roughly seven million people whose Social Security numbers or payment card details were involved; the laboratories notified the rest, or waited publicly for AMCA to tell them who the rest were. For millions of patients, the first time they ever saw the name American Medical Collection Agency was at the top of a letter explaining that it had exposed their data.

The Bankruptcy

Retrieval-Masters Creditors Bureau filed for Chapter 11 protection in White Plains on June 17, 2019 — fourteen days after Quest's disclosure made the breach public. Corporate deaths from cyberattack had been predicted for years; the court filings documented an actual case in detail.

The declaration filed by Russell Fuchs itemized what had killed the business, and none of it was a ransom. There was no extortion demand in this story at all; the attackers had monetized the data directly, in the card markets. What destroyed the company was the ordinary, lawful cost of having been breached. Mailing notices to more than seven million people cost about $3.8 million — of which Fuchs, the founder, personally lent the company $2.5 million. IT consultants and forensic investigators cost hundreds of thousands more. And the revenue side vanished at the same moment the costs arrived: Quest, LabCorp, and the other major clients severed the relationship within days of learning of the breach, as their own risk management required them to. Headcount fell from 113 at the end of 2018 to 25 by the filing.

The mechanism generalizes. For eight months the intrusion itself cost AMCA nothing; the costs came with disclosure — notification duties, remediation bills, legal exposure, and client flight arriving simultaneously, all landing on a small private company with no cyber-insurance tower or balance sheet to absorb them. The very features that made AMCA efficient at its niche — small, lean, specialized, cheap — made it incapable of surviving the consequences of its own failure. Large enterprises can absorb a breach; the company at the center of the chapter on Change Healthcare absorbed a response costing billions and remained in business. AMCA, at the bottom of the vendor chain, could not.

The legal aftermath took years and delivered almost nothing against the company itself: investigators found fault, but there was nothing left to take.

In March 2021, a coalition of 41 attorneys general — 40 states and the District of Columbia — in an investigation led by Indiana, Texas, Connecticut, and New York, settled with Retrieval-Masters over the breach. The settlement imposed a $21 million payment and suspended nearly all of it, on the straightforward ground that the company could not pay. It also imposed injunctive terms — an information security program, third-party assessments, incident-response obligations — a corrective regime for a firm that had largely ceased to operate. The company had moved to dismiss its own Chapter 11 case in March 2020; the bankruptcy court blessed the arrangement in October, and the case was dismissed that December; there was little to reorganize.

The money came instead from up the chain. The multidistrict litigation in New Jersey ground on against the laboratories — the entities with assets, and the entities patients had actually chosen to do business with. In 2026, LabCorp agreed to pay $35 million to settle the consumer claims against it, without admitting wrongdoing, in a settlement that as of this writing awaits final court approval; class members were offered modest cash payments or reimbursement of documented losses, plus years of credit monitoring. Claims involving other defendants proceeded on their own tracks. Seven years after the portal was compromised, the litigation was still allocating the bill.

For the 25 million patients, the remedy was limited. Their data — identity, finances, the fact and source of their medical debts — had been sold into the criminal markets, where it does not expire. The company responsible was gone, its penalty suspended, and the compensation on offer, years later, was fifty dollars and a monitoring subscription.

Lessons

AMCA never became a household name, even while it was mailing seven million letters. Among practitioners, though, it became a reference case, because it isolated a set of structural problems that later, larger incidents would restate at scale.

Vendor risk extends to subcontractors. Every organization manages the risk of its suppliers; almost none, in 2019, managed the risk of its suppliers' suppliers. For a Quest patient the chain ran from the draw station to Quest to Optum360 to AMCA — two contractual hops from the bedside, beyond any consent form and most risk registers. The practical lesson the laboratories drew, visible in the contract terms and vendor questionnaires that spread through the industry afterward, was that due diligence has to follow the data, not the contract: know every downstream party that holds your patients' information, bind them to standards, verify, and reserve the right to audit. The corollary is that the chain's weakest link will usually be its smallest and cheapest — the hundred-person firm doing the work nobody wanted to do in-house, at margins that fund no security program.

Breach detection often comes from outside the victim. AMCA's portal leaked data for eight months, and the first indication came from analysts watching a dark-web storefront on behalf of banks. Nothing inside the company caught it. Outsiders discover a substantial share of breaches, and AMCA is a clear healthcare example. A company too small to run monitoring is not thereby exempt from the eight-month silent breach; it will instead learn of the breach from outside, after the data has already been sold.

HIPAA's notification chain breaks down in multi-party breaches. The business-associate model routes duty upward: subcontractor tells contractor, contractor tells covered entity, covered entity tells patient. In the AMCA cascade that chain had to operate across two dozen organizations, through a failing company that alone knew the full scope and was shedding the staff who could compile it. The result was weeks of lag, public recrimination between Quest and its own vendor, notices arriving from a firm patients had never heard of, and totals that were still being revised months later. Notification law had contemplated a breach with one responsible party and one patient population. It had no good answer for a shared vendor whose breach affected two dozen covered entities at once.

The company's dissolution voided the penalties against it. The breach killed the company, but this was not a deterrent. The company's extinction meant the $21 million state penalty was suspended as uncollectable; the bankruptcy shielded what little remained; the founder's loan paid for the notification mailings. Every consequence that was supposed to discipline the conduct disappeared with the entity, while the harms — data in the markets, litigation costs, patients' exposure — persisted and migrated to parties one step removed from the failure. A liability regime that lands hardest on firms with the most to lose gives the least incentive to the marginal, thinly capitalized vendors who hold the same data with a fraction of the defenses. The labs, not the collector, ultimately paid, which is why the labs, not the collectors, changed their behavior.

AMCA held more data than its function required. The stolen data was valuable because of accumulation: identity, Social Security numbers, provider names, balances, and payment credentials, all resident on one small system whose business function required only a fraction of it at any moment. Nothing obliged the laboratories to pass Social Security numbers to a dunning contractor; nothing obliged the portal to retain card data once a payment cleared. After AMCA, "what does this vendor actually need, and for how long" became a standard question in healthcare data-sharing agreements — the small-scale version of the retention question raised by the Change Healthcare breach, where an intermediary held clinical history on most of a nation.

The commodity at the center of this breach was medical debt. The 25 million people exposed were exposed because the American health system had billed them, and they had not paid, or not paid fast enough — a population selected, almost by definition, for financial fragility, whose stolen data was exactly what an identity thief needs to make that fragility worse.

AMCA demonstrated, five years before the Change Healthcare attack, that the health system's exposure extended to its invisible middle layer — the contractors and subcontractors no patient chooses and none can evaluate, each one a concentration of other institutions' trust. The consequences were contained: one small company died, its clients paid settlements and rewrote their vendor contracts, and the sector filed the episode under third-party risk. The structure that produced the breach — data flowing down chains of intermediaries toward the cheapest firm willing to hold it — stayed in place. When the same structure failed again in 2024, the intermediary was the clearinghouse for half of American medical claims, not a hundred-person collections agency in Westchester.