Around June 15, 2026, Baylor Genetics identified suspicious activity and promptly secured affected systems.

 

What happened

According to the breach notice Baylor’s “investigation determined that an unauthorized third party accessed certain portions of our network, and certain data stored on our network, between June 11 and June 17, 2026. Baylor Genetics then conducted a detailed and time-intensive review to determine what information may have been involved and which individuals were potentially affected.” Baylor then reviewed the affected information to identify what it contained and who may have been affected, completing that process on or about July 30.

The company began providing written notices afterward. Potentially affected patient information varied by individual and may have included names, dates of birth, medical testing information, laboratory results, health insurance information and, for a very limited subset, Social Security numbers.

They said its laboratory continued operating, patient care was not disrupted, and it found no evidence that testing data or results were altered; therefore, retesting was unnecessary. It also said it was unaware of confirmed identity theft, fraud, or misuse associated with the incident at disclosure.

Baylor reported strengthening identity and access management, monitoring, and other security controls while coordinating with law enforcement and regulators. An August 14 filing with the California attorney general included a sample notification letter.

 

In the know

Because Baylor Genetics is headquartered in Houston, Texas provides the relevant state-law framework, although the company has not disclosed the physical location of the affected servers. Under the Texas Identity Theft Enforcement and Protection Act, identifiable information concerning a person’s health, healthcare, or payment for healthcare qualifies as sensitive personal information, as do names combined with unencrypted Social Security, government identification, or certain financial account information.

Section 521.053 generally requires affected residents to be notified without unreasonable delay and no later than 60 days after an organization determines that a breach occurred, subject to limited exceptions. An organization must also notify the Texas attorney general within 30 days when at least 250 Texas residents are affected. Separately, Chapter 546 of the Texas Insurance Code treats genetic information as confidential and generally prohibits a person or entity holding it from disclosing it without the individual’s authorization, subject to statutory exceptions.

Texas also regulates direct-to-consumer genetic testing through Business and Commerce Code Chapter 503A, which requires security measures, privacy notices and consent for certain uses or disclosures. However, that chapter excludes protected health information collected by HIPAA covered entities and business associates, so it should not automatically be applied to Baylor’s clinical records.

 

Why it matters

Genetic-testing organizations can hold information connecting a person’s identity with health findings, ancestry, and biological relationships, creating privacy risks that extend beyond ordinary account fraud. The 2023 23andMe breach demonstrates this wider impact. Regulators found that a credential-stuffing attack directly accessed more than 18,000 accounts, but information connected through the company’s DNA Relatives feature made data belonging to almost seven million customers accessible.

The information included health details, race or ethnicity, birth information, and data about genetically related individuals, while some stolen information was subsequently offered for sale online. Clinical genetic laboratories face similar risks even when raw DNA is not involved. In 2020, unauthorized access to an Ambry Genetics employee’s email account affected the protected health information of 232,772 patients, including names, diagnoses, other medical information, and, for some patients, Social Security numbers. The litigation produced a $12.25 million settlement, although Ambry denied wrongdoing.

The 2021 DNA Diagnostics Center incident also showed how long these risks can persist. Attackers accessed an archived database containing personal information collected between 2004 and 2012 and inherited through a company acquisition, even though the database was no longer actively used.

See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)

 

FAQs

What protections does GINA provide?

The Genetic Information Nondiscrimination Act prohibits covered health insurers and employers from discriminating based on genetic information. The EEOC explains that genetic information includes genetic test results, family medical history, and participation in genetic services.

 

Does GINA cover life, disability, or long-term care insurance?

No, GINA does not generally regulate the use of genetic information by life, disability, or long-term care insurers. The National Human Genome Research Institute notes that some states provide additional protections in these areas.

 

Does HIPAA protect every genetic test result?

HIPAA protects genetic information held by covered healthcare organizations and their business associates, but it does not apply to every direct-to-consumer testing company.