The Department of Health and Human Services (HHS) has settled a HIPAA investigation with Ambry that stemmed from a phishing attack.
What happened
On September 17th, 2026, The HHS’ Office for Civil Rights (OCR) announced that a settlement had been reached with Ambry Genetics, an organization that does genetic testing for cancer and other diseases. The OCR had been investigating the California-based company after they were the victim of a phishing attack. The OCR alleged that Ambry had violated HIPAA because of how they handled and prepared for the attack.
Ultimately, the OCR and Ambry agreed to a resolution, which involves Ambry paying $700,000 to the OCR and implementing a corrective action plan. The OCR will also monitor Ambry’s compliance for two years.
Going deeper
Ambry first discovered they had been breached in January of 2020, when the company learned that an employee’s email account had been compromised in a phishing attack. The attack resulted in protected health information (PHI) of 225,370 individuals to be stolen by a threat actor. Data included names, addresses, Social Security numbers, dates of birth, medical and treatment information, and financial information.
For Ambry, the penalty hasn’t been the only consequence of the 2020 data breach. In 2023, Ambry agreed to a settlement of $12.25 million following a class action suit, which alleged that Ambry had been negligent in protecting individuals’ PHI. The final hearing took place on March 6th, 2023, and the case was officially settled.
In the know
According to the HHS’ press release on the issue, the OCR had found that Ambry had potentially violated multiple provisions of the Security Rule under HIPAA, including:
- Failing to conduct a risk analysis of potential vulnerabilities in Ambry’s electronic PHI (ePHI) systems.
- Failing to terminate access to ePHI when an employment arrangement ends or access is otherwise no longer needed.
- And failing to assign a unique name and/or number of tracking user identity in ePHI systems.
As part of Ambry’s corrective plan, they will be required to:
- Conduct an accurate and thorough risk analysis to determine if they have any potential vulnerabilities to their ePHI systems.
- Develop a plan to mitigate any risks that are discovered.
- Develop and revise, if necessary, their current policies to comply with HIPAA.
- Implement unique user identification for all systems that hold ePHI.
- Ensure that every employee or contractor is trained in the Security Rule’s policies and procedures.
What was said
According to the OCR Director, Paula M. Stannard, “Conducting a compliant risk analysis, engaging in risk management, and full implementation of the Security Rule provisions continue to be the foundation for effective cybersecurity and the best cyberdefense.”
Stannard added that email phishing is fairly common and can “reveal HIPAA Security Rule deficiencies.”
The big picture
The HHS has been cracking down on enforcing the Security Rule over the last few years, and this marks its sixth resolution in 2026.
Most recently, in August of 2026, the HHS resolved a case against Azul Vision, which alleged that the vision healthcare provider failed to comply with HIPAA’s Privacy rule by denying patient access to PHI. The case resulted in a penalty of $50,000, along with a corrective action plan.
These cases, among others, show that the HHS is actively monitoring compliance with every part of HIPAA. With the use of corrective action plans, the HHS shows their commitment to keeping PHI secure and holding organizations accountable to HIPAA requirements.
FAQs
Why did Ambry face a penalty when other companies haven’t?
Every time an organization is breached and the breach is reported to the HHS (which is also required under HIPAA), the incident is investigated. In many cases, under HIPAA, organizations are doing everything that is required to keep data safe, even if the methods are unable to prevent a breach.
Even if an organization doesn’t violate HIPAA, they may still be found to have been irresponsible in preparation or handling, which is an issue that often comes up if an organization faces a class action lawsuit. Ultimately, under HIPAA, the OCR believes some breaches could not have been reasonably prevented, and thus won’t fine them. In this case, the OCR believes Ambry could have prevented the issue, and thus penalized the organization.
Will Ambry face any other consequences for this phishing attack?
It’s unlikely that the case will be revisited by the OCR or other legal entities, so long as Ambry follows the corrective action plan and does not have other security incidents. Nevertheless, even if Ambry doesn’t face any more legal troubles, the cost of the penalty, alongside the costs of the corrective action plan, will likely continue to impact Ambry.
