Skip to content
Data breachContained

Baylor Genetics data breach exposes health data of 2.8 million patients (2026)

Genetic-testing firm Baylor Genetics disclosed in late July 2026 that an intrusion into its network had exposed the protected health information of more than 2.8 million patients.

Victim
Baylor Genetics
records
2.8M

On or about 30 July 2026, Baylor Genetics โ€” a Houston-based genetic-testing and precision-medicine laboratory โ€” completed its review of a network intrusion and began notifying individuals that their personal and protected health information had been exposed. The company ultimately determined that the incident affected more than 2.8 million patients, making it one of the larger U.S. healthcare data breaches disclosed during the summer.

What happened

Baylor Genetics identified suspicious activity within its computer network on or around 15 June 2026. A subsequent forensic investigation concluded that an unauthorized third party had accessed portions of the network and certain stored data between 11 and 17 June 2026. The company then undertook a lengthy review to determine exactly what information was involved and who was affected, finishing that process on or about 30 July.

The exposed information varied by individual but could include names, dates of birth, medical testing information, laboratory results, and health-insurance details. For a limited subset of people, Social Security numbers were also involved โ€” the category most readily abused for identity theft.

Response

Baylor Genetics said it secured its environment, engaged outside specialists, and began mailing written notices to affected individuals after completing its data review. The company offered complimentary credit-monitoring and identity-theft-protection services to at least some of those notified. State filings reported large numbers of affected residents across multiple states, including hundreds of thousands in Texas alone.

Why it matters

Genetic-testing laboratories hold some of the most sensitive data any organisation can custody โ€” combining medical, laboratory, and identity information that cannot be reissued like a password. A breach at this scale underscores both the attractiveness of healthcare and genomics providers to intruders and the long tail between an intrusion, its discovery, and the eventual notification of millions of patients.

Timeline

  1. Baylor Genetics identifies suspicious activity within its computer network.

  2. An unauthorized third party begins accessing portions of the network and stored data (access continues through 17 June).

  3. The company completes its review of the affected data, determines more than 2.8 million people were impacted, and begins notifying them.

Sources

  1. hipaajournal.comhttps://www.hipaajournal.com/baylor-genetics-data-breach/
  2. cybersecuritydive.comhttps://www.cybersecuritydive.com/news/baylor-genetics-cyberattack-compromise-patient-data-genetic-testing/828019/
  3. paubox.comhttps://www.paubox.com/blog/baylor-genetics-reports-breach-involving-patient-data
  4. baylorgenetics.comhttps://www.baylorgenetics.com/securityupdate/

Related incidents