A Houston-based genetics testing laboratory is notifying patients and staff following a cyberattack that potentially exposed their personal and medical information. An official filing with the Department of Health and Human Services (HHS) lists 2,810,878 people affected by the incident.
Baylor Genetics stated that the breach took place within a limited portion of its IT environment. The company detected suspicious activity on or around June 15 and subsequently confirmed that unauthorized access occurred between June 11 and June 17.
Exposed Information
The compromised data varies between patients and staff members:
- Patients: Names, dates of birth, laboratory test results, medical testing details, and in limited cases, health insurance information or Social Security numbers.
- Employees: Certain current and former employees had Social Security numbers, government identification, and financial account data exposed.
The firm concluded its review around July 30, after which it began notifying affected individuals and reporting the incident to regulators.
Response and Operations
In response to the cyberattack, Baylor Genetics stated that it has enhanced its security controls and is offering identity protection resources to those impacted. The company noted that it has no evidence of misuse, stating that it is not aware of any confirmed identity theft, fraud, or misuse of personal information related to the incident.
Additionally, the firm reported that laboratory operations continued without interruption throughout the investigation, with no impact on its ability to provide genetic testing services.


