2026 Baylor Genetics — HHS 2,810,878; Jun 11–17 intrusion; genetic lab results + SSN subset
Data compromised
Patients: names, DOB, medical testing info, lab results, health insurance (subset with SSNs). Employees: SSNs, government IDs, financial account info. Test result integrity not affected per company.
Technical writeup
Verified company notice plus HHS OCR census — August 2026. Baylor Genetics (Houston clinical genomics laboratory) reported to the U.S. Department of Health and Human Services that approximately 2,810,878 individuals were affected by a hacking/IT incident involving a network server. Hearst Television’s National Consumer Unit (WDSU, Aug 27, 2026) cited the federal filing. Unauthorized access occurred between June 11 and June 17, 2026; suspicious activity was identified around June 15; file review completed July 30; letters began August 14. Fields may include names, DOB, addresses, SSNs, diagnoses, medical conditions, laboratory results, and health insurance (varied by person); employees may have SSNs, government IDs, and financial account data. State samples in reporting: ~248,430 Texas, ~56,636 Massachusetts, ~50,495 Illinois, ~27,243 Washington, 2,630 Vermont, ~4,532 Rhode Island. Baylor states operations continued, results were not altered, and no confirmed misuse at indexing. recordsAffected 2810878 from HHS filing cited by Hearst; companyConfirmed true.
Root cause
HHS OCR filing: hacking/IT incident on network server Jun 11–17, 2026; discovered Jun 15; review completed Jul 30
References
- https://www.baylorgenetics.com/securityupdate/
- https://www.wdsu.com/article/baylor-genetics-medical-data-breach/73534860
- https://www.hipaajournal.com/baylor-genetics-data-breach/
- https://www.cybersecuritydive.com/news/baylor-genetics-data-breach/758123/
- https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf