A data security incident at Baylor Genetics earlier this year exposed the confidential personal data of more than 2.8 million people.
Based in Houston’s Texas Medical Center, Baylor Genetics functions as a specialised genomic testing and clinical diagnostics facility concentrating on customised hereditary medicine, rare condition identification, and high-tech DNA decoding. Formed as a partnership between H.U. Group Holdings and the Baylor College of Medicine, the enterprise caters to medical practitioners and patients alike.
In an official disclosure posted on its website, Baylor Genetics said that suspicious network activity was detected on June 15. The healthcare organisation promptly engaged independent cyber security specialists to investigate the breach and evaluate its extent.
It also took steps to contain the incident, secure the affected network and notified relevant law enforcement authorities the same.
“The investigation determined that an unauthorised third party accessed certain portions of our network, and certain data stored on our network, between June 11 and June 17, 2026,” Baylor Genetics said.
The compromised information included names, dates of birth, medical testing information, laboratory test results, health insurance details, and Social Security numbers. For current and former employees, the exposed information included Social Security numbers, government-issued identification numbers, and financial account information.
Initial filings submitted to the Texas state regulator indicated that at least 248,430 residents were affected by the security incident. However, a subsequent federal filing with the U.S. Department of Health and Human Services revealed that the total scale of the breach reached 2,810,878 individuals nationwide.
Following the cyber attack, Baylor Genetics secured the compromised systems, enhanced its network security and access protocols, and deployed extra safeguards to protect confidential data against future threats.
While Baylor Genetics found no evidence of the compromised information being misused, it advised all affected individuals to regularly monitor their credit reports, account and benefit statements and report any suspicious activity to law enforcement authorities, including the police and the state attorney general.
No known threat actor claimed responsibility for the cyberattack at the time of publication. Baylor Genetics also did not details regarding the perpetrators, the exact volume of exfiltrated data, and whether a ransom demand was made.
Please take 30 seconds to register
Already have an account? Sign in
"AI-led spear phishing worries me the most" - Darktrace's Dave Palmer
"Crisis or no crisis; security needs to be the same"
"People need to understand that there isn't an invisible force-field that's protecting them"
"The community needs to recognise and understand crime"
"We've seen a marked increase in social engineering attacks"
"AI-led spear phishing worries me the most" - Darktrace's Dave Palmer
"Crisis or no crisis; security needs to be the same"
"People need to understand that there isn't an invisible force-field that's protecting them"
"The community needs to recognise and understand crime"
"We've seen a marked increase in social engineering attacks"
$12M Vanishes in Crypto Heist Targeting Cork Protocol’s Depeg Market
$600 million stolen & returned in biggest ever crypto heist
10-month cyber attack exposes personal data of South Korean diplomats
Sécuriser les infrastructures critiques à l’ère de NIS2 : confiance, conformité, performance et résilience
Building cyber-resilience across your digital supply chain
Building Agentic AI security awareness beyond the security team
Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
