Skip to content
Ambry Genetics Settles HIPAA Violations After Phishing Attack Exposes PHI

Ambry Genetics Settles HIPAA Violations After Phishing Attack Exposes PHI

First seen 19 Sep 2026, 18:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 19:58 UTC
  • Ambry Genetics settled for $700,000 due to HIPAA violations from a phishing attack.
  • The breach affected the PHI of 225,370 individuals, including sensitive personal data.
  • The HHS OCR emphasized the importance of risk analysis and management in cybersecurity.

On September 17, 2026, the HHS Office for Civil Rights announced a settlement with Ambry Genetics regarding HIPAA Security Rule violations. The company, which provides genetic testing services, reported a phishing attack in January 2020 that compromised an employee's email account. This breach potentially exposed the protected health information (PHI) of 225,370 individuals, including names, addresses, and Social Security numbers. The OCR found that Ambry failed to conduct a thorough risk analysis and did not properly manage access to ePHI. As part of the settlement, Ambry agreed to pay $700,000 and implement a corrective action plan monitored over two years. The incident highlights the ongoing risks associated with email phishing in the healthcare sector.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2020-01-01
Phishing attack discovered
Ambry Genetics identified a phishing attack that compromised an employee's email account, leading to a data breach.
Hhs
2020-03-01
Breach report filed
Ambry Genetics filed a breach report with the OCR following the phishing incident, detailing the exposure of PHI.
Hhs
2026-09-17
Settlement announced
The HHS OCR announced a settlement with Ambry Genetics, requiring a $700,000 payment and corrective action plan.
Hhs

More articles in this cluster (3)

Following this threat?

Track Ambry Genetics Corporation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed