01Summary
The Houston-based genetic testing company spotted suspicious activity around 15 June 2026. An investigation, completed around 30 July, found an unauthorised party in its network from 11 to 17 June. Notifications began on 14 August, and the HHS filing lists 2,810,878 people. Data includes names, birth dates, addresses, SSNs, diagnoses, lab results and other test information, plus employee SSNs, ID numbers and financial details. The US Department of Veterans Affairs criticised the delay in warning patients.
02Victims and impact
Countries affected
- United States
03Data exposed
Data types
- Names
- Dates of birth
- Social Security numbers
- Diagnoses
- Genetic and laboratory test results
- Employee financial data
04Timeline
- 2026-06-11Unauthorised access begins.
- 2026-06-15Suspicious activity detected.
- 2026-07-30Investigation completed.
- 2026-08-14Notification letters begin.
05Reaction and fallout
Public reaction
The Department of Veterans Affairs criticised the delayed warning.
06Disclosure and media
Publishing organisations
- Cybernews
- HIPAA Journal
- Cybersecurity Dive
07Sources
References
- [1]HIPAA Journal: https://www.hipaajournal.com/baylor-genetics-data-breach/
- [2]Cybersecurity Dive: https://www.cybersecuritydive.com/news/baylor-genetics-cyberattack-compromise-patient-data-genetic-testing/828019/









