Hhs Ambry Genetics Settles HIPAA Violations After Phishing Attack Exposes PHI
Article Content
- •Ambry Genetics settled for $700,000 due to HIPAA violations from a phishing attack.
- •The breach affected the PHI of 225,370 individuals, including sensitive personal data.
- •The HHS OCR emphasized the importance of risk analysis and management in cybersecurity.
On September 17, 2026, the HHS Office for Civil Rights announced a settlement with Ambry Genetics regarding HIPAA Security Rule violations. The company, which provides genetic testing services, reported a phishing attack in January 2020 that compromised an employee's email account. This breach potentially exposed the protected health information (PHI) of 225,370 individuals, including names, addresses, and Social Security numbers. The OCR found that Ambry failed to conduct a thorough risk analysis and did not properly manage access to ePHI. As part of the settlement, Ambry agreed to pay $700,000 and implement a corrective action plan monitored over two years. The incident highlights the ongoing risks associated with email phishing in the healthcare sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Ambry Genetics Corporation in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…