Patient & Employee Data Exposed in Baylor Genetics Cybersecurity Incident
Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.
Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston. The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity. The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.
Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.
Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Baylor Genetics said the incident did not impact its laboratory operations, which continued without interruption throughout the investigation, and there was no impact on the company’s ability to provide genetic testing services. Baylor Genetics has enhanced its security and monitoring controls, strengthened identity and access management, and has implemented additional security controls to prevent similar incidents in the future. Complimentary credit monitoring and identity theft protection services have been offered to at least some patients.
The data breach has been reported to regulators; however, it is currently unclear how many patients and employees had data compromised in the incident. The breach has affected patients in California, as the California Attorney General was notified about the data breach, as was the Vermont Attorney General. At least 2,630 Vermont residents have been affected.
The post Patient & Employee Data Exposed in Baylor Genetics Cybersecurity Incident appeared first on The HIPAA Journal.
The Sixth Generation of Patient Access – Health API Guy
MakeForms Becomes the First Form Builder Platform to Fully Automate HIPAA Compliance – Including Instant, Self-Serve Business Associate Agreements – StreetInsider
HIPAA-compliant marketing platform Ours Privacy lands $15M amid growing pixel concerns – Fierce Healthcare
CARIN Alliance builds trust outside HIPAA – Healthcare Finance News
American Addiction Centers & Oculus Pathology Disclose Hacking Incidents – The HIPAA Journal
American Addiction Centers & Oculus Pathology Disclose Hacking Incidents
Hacking incidents have been announced by American Addiction Centers in Tennessee and Oculus Pathology in Texas. Regional Center of Orange County in California has discovered the improper disposal of paper records.
American Addiction Centers, Tennessee
American Addiction Centers, a Brentwood, Tennessee-based provider of addiction treatment services at more than 30 facilities across the United States, has notified the California Attorney General about a recent security incident involving a third-party vendor. According to the notice, suspicious activity was identified within its Salesforce environment on June 5, 2026.
The forensic investigation determined on June 12, 2026, that there had been unauthorized access to its Salesforce instance on May 12, 2026, and data was exfiltrated from that system. The forensic investigation confirmed that the incident did not affect any other systems. The data review confirmed that names, contact information, Social Security numbers, and health insurance information were acquired, along with brief descriptions that patients provided related to their health. The affected data related to initial outreach to American Addiction Centers.
American Addiction Centers said that security measures had been implemented prior to the breach and that it will continue to review its security measures to further protect and monitor its Salesforce environment, and complimentary credit monitoring and identity theft protection services have been made available. At present, it is unclear how many individuals have been affected.
Get The FREE
HIPAA Compliance Checklist
Immediate Delivery of Checklist Link To Your Email Address
Please Enter Correct Email Address
Your Privacy Respected
HIPAA Journal Privacy Policy
Oculus Pathology, Texas
Oculus Pathology, an Austin, Texas-based anatomic and clinical pathology group that provides services in several U.S. states, has announced an email security incident that has exposed patient information. Suspicious activity was identified within an employee’s email account on April 1, 2026. An investigation was launched to determine the nature and scope of the activity, and it was determined that a small number of employee email accounts had been accessed by an unauthorized third party between March 31, 2026, and April 2, 2026.
Data review specialists were engaged to investigate the incident. Data exposed in the incident includes personally identifiable information such as names, birth dates, Social Security numbers, driver’s license numbers/state ID numbers, and individual tax identification numbers. Some financial account numbers and payment card numbers were exposed, in some cases with access information.
In addition, protected health information was exposed, including clinical information, health insurance information, diagnoses, treatment and procedure information, treatment locations, medical record numbers, Medicare numbers, prescription information, and patient IDs. The data review is ongoing. Oculus Pathology has yet to announce how many individuals have been affected in total.
Regional Center of Orange County, California
Regional Center of Orange County, a Santa Ana, California-based nonprofit organization that provides services to approximately 29,000 Orange County residents with autism, epilepsy, cerebral palsy, and intellectual and cognitive disabilities, has announced a data security incident that has exposed sensitive data. The incident involved paper records that were mistakenly disposed of by a Janitorial service contracted to clean its Cypress office. The incident occurred on May 27, 2026, and was discovered on May 28, 2026. Documents had been disposed of in regular trash bins rather than being sent for secure destruction. Attempts were made to retrieve the documents; however, the trash had already been collected.
It was not possible to determine the exact patients involved or the specific types of information, so notification letters have been sent to all individuals who received services at the Cypress office. Data likely exposed included names, addresses, birth dates, phone numbers, email addresses, unique client identifiers, and personal health information. Regional Center of Orange County said it is reviewing and strengthening internal procedures, staff training, and vendor oversight to prevent similar incidents in the future, and the affected individuals have been offered complimentary credit monitoring and identity theft protection services.
The post American Addiction Centers & Oculus Pathology Disclose Hacking Incidents appeared first on The HIPAA Journal.
