Baylor Genetics: Data Breach Affects 2.8 Million Patients

Another major healthcare data breach has recently been announced, involving unauthorized access to systems containing the electronic protected health information of more than 2.8 million individuals.

Baylor Genetics is a Texas-based genomics diagnostics firm that specializes in clinical genetic testing, comprehensive clinical sequencing, rare disease diagnosis, and precision medicine. In August, the company disclosed a cybersecurity incident involving unauthorized access to its network between June 11, 2026, and June 17, 2026. According to a statement released by the company at the time, the incident impacted a limited portion of its information technology environment.

The forensic investigation determined that the compromised parts of the network contained individuals’ personal and protected health information that had been created by Baylor Genetics or been provided by healthcare providers that use the company’s genetic testing services. Data potentially compromised in the incident included dates of birth, medical and laboratory test results, and health insurance information. A subset of the affected individuals also had their Social Security numbers exposed or stolen in the incident. Employee data was also compromised, including names, Social Security numbers, and financial account information.

The forensic investigation concluded on July 30, 2026; shortly thereafter, notification letters were mailed to the affected individuals. Baylor Genetics said that at the time of issuing notification letters, it was unaware of any misuse of the impacted data and had found zero evidence to suggest that the individuals behind the cyberattack manipulated any test result data.

In response to the attack, and guided by the forensic analysis, Baylor Genetics implemented additional security measures and has improved identity and access management. At the time of the initial announcement, it was unclear exactly how many individuals had been affected. The Department of Health and Human Services (HHS) Office for Civil Rights breach portal has recently listed the breach summary, showing that this was a major data breach involving the electronic protected health information of 2,810,878 individuals.

This is the latest in a string of major data breaches at healthcare providers, health plans, and medical technology companies. Other companies that have recently announced breaches involving millions of patient records include DentaQuest, Aesto, AdaptHealth, CareCloud, Medtronic, and Unlimited Technology Systems.

HIPAA
Compliance
Checklist

Simple Guidelines
Immediate PDF Download

Immediate Access

Privacy Policy

Download Free Checklist

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/