Criterica Intelligence — production models trained on real court records, not synthetic data
Data Breach — MDL No. 2904

American Medical Collection Agency, Inc.

U.S. District Court for the District of New Jersey

The American Medical Collection Agency, Inc., Customer Data Security Breach litigation was centralized before Judge Jamel K. Semper in the District of New Jersey in July 2019, consolidating claims arising from a data security breach at AMCA, a medical billing and collections vendor, that exposed personal and health-billing information for patients across numerous healthcare providers and laboratories that used AMCA's services. This vendor-breach structure — a single compromised intermediary affecting many unrelated downstream entities — is a distinct pattern within the data-breach MDL category.

With 42 pending actions, resolution risk in this docket is shaped by that multi-provider structure: rather than a single defendant's data-security practices being the sole focus, claims may implicate questions about which downstream healthcare provider's contractual and data-security obligations apply to a given plaintiff's exposure, in addition to AMCA's own security practices. That layered structure can extend the range of factual and legal questions relative to a single-company breach, even at a comparatively modest pending-action count.

Vendor and third-party-breach MDLs like this one are an increasingly common pattern in the data-breach category, reflecting how concentrated points of failure in shared service providers can generate litigation spanning many otherwise-unrelated downstream businesses and their customers. Criterica Intelligence's platform tracks this vendor-breach structural pattern — distinguishing it from single-company breach litigation — across every active MDL, since the multi-party structure meaningfully affects how duration and resolution risk should be assessed. A companion capital brief on this docket is available through Criterica Capital.

Frequently Asked Questions
What happened in the AMCA breach?

A data security breach at American Medical Collection Agency, a medical billing and collections vendor, exposed personal and health-billing information for patients across numerous healthcare providers and laboratories that used its services.

Why does this docket involve claims from patients of many different providers?

Because AMCA served as a shared vendor for numerous healthcare entities, its breach exposed data belonging to patients across all of those unrelated downstream providers and laboratories, not just AMCA's own direct customers.

How does a vendor breach affect resolution risk compared to a single-company breach?

It can extend the range of factual and legal questions, since claims may implicate a downstream provider's own data-security and contractual obligations in addition to the vendor's practices, layering additional complexity onto the standard data-breach analysis.

Is this kind of vendor-breach structure common in data-breach MDLs?

It is an increasingly common pattern, reflecting how a single compromised shared service provider can generate litigation spanning many otherwise-unrelated downstream businesses — a structure Criterica Intelligence tracks distinctly from single-company breach litigation.

Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.

← All Pending MDLsFunding brief on Criterica Capital →