← Blog

Baylor Genetics Breach: 2.8M on HHS OCR

Share on X

August 27, 2026: Baylor Genetics reported to the U.S. Department of Health and Human Services that approximately 2,810,878 people were affected by a network-server hacking incident between June 11 and June 17, 2026. Hearst Television’s National Consumer Unit cited the federal filing; fields may include names, dates of birth, addresses, Social Security numbers, diagnoses, medical conditions, and laboratory results. Canonical: baylor-genetics-cyber2026. Sources: WDSU/Hearst, Baylor Genetics notice, HIPAA Journal.

Clinical genomics is not a loyalty-card database. A carrier-screening or oncology panel ties your name to hereditary risk, pregnancy planning, or tumor markers — data thieves can weaponize that context in ways a generic “your account was hacked” email never could.

What happened: Baylor Genetics data breach timeline

Baylor Genetics (Houston) detected suspicious activity around June 15, 2026, secured systems, and determined an unauthorized third party accessed portions of its network from June 11 through June 17. A file review completed around July 30 identified affected patients and current/former employees. Notification letters began going out August 14, per Hearst reporting.

The company filed with HHS at 2,810,878 individuals — one of the largest U.S. healthcare breaches cataloged in 2026 so far. State breakdowns cited in reporting include roughly 248,430 Texas, 56,636 Massachusetts, 50,495 Illinois, 27,243 Washington, and 2,630 Vermont residents, plus about 4,532 Rhode Island residents in the company notice.

What data was exposed in the Baylor Genetics breach?

Per the company security update and HIPAA Journal, patient fields varied by person and may include:

  • Names and dates of birth
  • Medical testing information and laboratory test results
  • Health insurance information
  • Social Security numbers (described as a limited subset)

Employee data may include SSNs, government-issued IDs, and financial account information. Baylor Genetics states genetic test results were not altered, lab operations continued, and it is unaware of confirmed misuse at indexing.

Why you might not recognize the Baylor Genetics name

Baylor Genetics performs testing for hospitals and other laboratories. Your notice may reference a ordering provider or a third-party lab brand rather than “Baylor Genetics” on the envelope. That is common in reference-lab economics — and it confuses patients who never knowingly chose the vendor.

Who is at risk?

Patients whose genetic or molecular tests ran through Baylor Genetics in the exposure window (and potentially broader retention). Employees with HR/payroll data on the network. Anyone whose SSN or diagnosis appears in a letter faces elevated identity-theft and medical-ID fraud risk.

Healthcare breach context in 2026

HHS OCR breach reporting hit record levels in 2025; 2026 continues the climb. Baylor joins other multi-million-row lab and RCM incidents on BreachHistory this year. Attackers target genomics vendors because the data is dense, permanent, and poorly understood by patients watching only retail HIBP loads.

What Baylor Genetics said

The public security update describes enhanced monitoring, strengthened identity and access management, and complimentary identity protection through IDX for some individuals. The company recommends reviewing account statements, Explanation of Benefits statements, and credit reports.

Was I affected by the Baylor Genetics data breach?

Wait for your notification letter or check state AG listings if you had genetic testing routed through a major hospital system in 2025–2026. Do not trust random “Baylor Genetics leak download” posts — verified facts come from the company, HHS, or your provider.

Action items

  1. Read your letter carefully for which fields (SSN, lab results, insurance) apply to you.
  2. Enroll in offered IDX/credit monitoring if provided; set calendar reminders before expiry.
  3. Review EOBs and lab bills for services you did not receive — classic medical-ID fraud signal.
  4. Place a credit freeze or fraud alert if your SSN was listed (free under federal law).
  5. Ignore SMS or email “urgent genetic results” links; use your hospital portal or call your clinician.

Canonical record and sources

Catalog: baylor-genetics-cyber2026 — recordsAffected 2810878 (HHS filing via Hearst). Related: CareCloud 3.76M, UTS 3.8M.

Search coverage: Baylor Genetics data breach, Baylor Genetics hack 2026, 2.8 million genetic test breach, Houston lab PHI leak, was I affected Baylor Genetics, medical lab ransomware 2026.

Genetic-test PHI is irreversible — you cannot rotate a diagnosis like a password. EOB and lab-result phishing spikes for months after clinical lab notices.

Airport parking and WiFi sign-ups feel low-risk until a scammer knows your plate, postcode, and travel dates. MAG-scale contact lists power convincing “your Stansted booking failed” SMS.

Museum and nonprofit breaches often sit quiet for a year before letters — class actions follow when members learn from press, not mail.

Crypto travel platforms hold passports and wallet addresses together — a rare combo for KYC bypass and SIM-swap follow-on.

Hashed passwords still matter when people reuse the same string on email and exchange accounts. Rotate Travala + every reuse; enable hardware MFA on email first.

Texas hunting-license victims already have a dedicated BreachHistory blog — do not confuse TPWD with Texas DPS (a separate 2024 driver-record incident).

Carhartt and Boston Scientific August 2026 blogs are live on BreachHistory — check those canonical pages before re-sharing actor-inflated counts.

Freeze credit when SSN appears in a lab or museum letter; monitor Explanation of Benefits when only insurance IDs were listed.

NCSC and ICO guidance after UK breaches: ignore unexpected payment links; airports never ask for card details by cold call.

Open bookmarks to official portals now so you are not searching under panic later.

Secondary scams include fake IDX enrollment portals and fake “class action payout” forms that harvest more PII.

Support agents become targets when CRM context leaks — brief them before customers forward breach screenshots.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.