Baylor Genetics
Incident posture
Linked entities
- Victim
- Baylor Genetics
- Threat actors
- 0 actors
- Sources
- 11 sources
Timeline
Summary
Baylor Genetics disclosed a cybersecurity incident in which an unauthorized third party accessed a limited portion of its information technology environment and obtained certain personal and medical data. The accessed information included patients’ names, dates of birth, laboratory test results, health insurance details, and, for a limited subset, Social Security numbers, as well as employees’ Social Security numbers, government‑issued identifiers, and financial account data. The company stated that its investigation, conducted with external forensic experts and law enforcement, found no evidence of altered test results or confirmed misuse of the exposed data, and that laboratory operations continued uninterrupted. Notification letters were sent to potentially affected individuals, and the firm reported that it has strengthened security controls and enhanced monitoring following the incident.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On or around June 15, 2026, Baylor Genetics identified suspicious activity within a limited portion of its information technology environment. The company launched an investigation with outside cybersecurity and digital forensic specialists. The investigation determined that an unauthorized third party accessed portions of the network between June 11 and June 17, 2026. A review to determine what information was involved and who was affected was completed on or about July 30, 2026. After completing the review, Baylor Genetics began notifying potentially affected individuals.
For patients, the information that may have been exposed included full names, dates of birth, medical testing information, laboratory test results, health insurance information, and Social Security numbers for a limited subset of patients. For current and former employees, the information that may have been exposed included Social Security numbers, government‑issued identification numbers, and financial account information. The company stated there was no evidence that hackers had modified patients’ test results. Laboratory operations continued without interruption and the ability to provide genetic testing services was not affected. The exposure created a risk of identity theft, medical identity theft, and insurance fraud for those whose data was accessed.
Upon identifying the incident, Baylor Genetics secured its systems, engaged leading independent cybersecurity and forensic specialists, notified law enforcement, and implemented additional security measures. The company strengthened security controls, enhanced monitoring, coordinated with law enforcement and regulators, and continued to notify potentially affected individuals. Baylor Genetics stated it was not aware of any confirmed identity theft, fraud, or misuse of personal information linked to the incident and that its systems remained operational and its environment secure.
Sources
Sources available to members: 11 sources.