Skip to content
Data breachContained

Baylor Genetics data breach exposes 2.8 million people

Houston-based genetic-testing company Baylor Genetics disclosed a data breach affecting about 2.8 million people after an unauthorized party accessed portions of its network and exfiltrated sensitive health and personal information.

Victim
Baylor Genetics
records
2.8M

In late August 2026, Houston-based genetic-testing company Baylor Genetics publicly confirmed a data breach affecting approximately 2.8 million people. The company said an unauthorized third party had accessed portions of its network between 11 and 17 June 2026, roughly a week, after it detected suspicious activity in a limited part of its IT environment on or around 15 June.

An investigation completed at the end of July determined which data had been involved, and Baylor Genetics began sending notification letters on 14 August, with the scale of the incident becoming widely reported later in the month. The exposed information varied by individual and could include names together with dates of birth, addresses, medical testing information, laboratory results, diagnoses and health-insurance details โ€” and, for a subset of people, Social Security numbers.

What happened

Baylor Genetics is a joint venture that performs clinical genetic and genomic testing, meaning the compromised records include unusually sensitive categories of health data. The company said it had not confirmed any resulting identity theft or misuse tied to the breach, and it moved to contain the intrusion and notify affected individuals. The delay between the June intrusion and later notification drew public criticism, including from the U.S. Department of Veterans Affairs over the timing of the warning.

Why it matters

Genetic-testing firms hold some of the most sensitive personal data in existence โ€” diagnostic results, medical conditions and, in some cases, government identifiers โ€” that cannot be reset like a password. A breach on this scale reinforces the heightened duty of care on laboratories and their vendors to protect genomic and health information, and the reputational cost of slow breach notification.

Timeline

  1. Baylor Genetics detects suspicious activity in a limited portion of its IT environment.

  2. The forensic investigation concludes that an unauthorized party accessed the network between 11 and 17 June.

  3. Notification letters to potentially affected individuals begin going out.

  4. The breach is widely reported, with the affected population placed at about 2.8 million people.

Sources

  1. baylorgenetics.comhttps://www.baylorgenetics.com/securityupdate/
  2. hipaajournal.comhttps://www.hipaajournal.com/baylor-genetics-data-breach/
  3. cybernews.comhttps://cybernews.com/security/millions-of-patients-warned-after-dna-testing-data-breach/
  4. cybersecuritydive.comhttps://www.cybersecuritydive.com/news/baylor-genetics-cyberattack-compromise-patient-data-genetic-testing/828019/

Related incidents