Full Report
On or around June 15, 2026, Baylor Genetics identified suspicious activity within a limited portion of its information technology environment. We immediately secured affected systems and launched a comprehensive investigation with the assistance of leading independent cybersecurity and digital forensic specialists. The investigation determined that an unauthorized third party accessed certain portions of our network, and certain data stored on our network, between June 11 and June 17, 2026. Baylor Genetics then conducted a detailed and time-intensive review to determine what information may have been involved and which individuals were potentially affected. That review was completed on or about July 30, 2026. Following completion of this review, Baylor Genetics provided notice to potentially affected individuals in accordance with applicable legal requirements.
Analysis Summary
# Incident Report: Baylor Genetics Data Breach
## Executive Summary
Between June 11 and June 17, 2026, Baylor Genetics experienced a targeted cybersecurity incident where an unauthorized third party gained access to a limited portion of its network. The breach resulted in the potential compromise of sensitive patient health information and employee personal data, though laboratory operations remained unaffected. The organization secured its environment, conducted a forensic review, and completed its data impact assessment by July 30, 2026.
## Incident Details
- **Discovery Date:** June 15, 2026
- **Incident Date:** June 11 – June 17, 2026
- **Affected Organization:** Baylor Genetics
- **Sector:** Healthcare / Genetic Testing Laboratory
- **Geography:** United States (Headquartered in Houston, Texas)
## Timeline of Events
### Initial Access
- **Date/Time:** June 11, 2026
- **Vector:** Not disclosed (Investigation confirmed unauthorized network access)
- **Details:** An unauthorized actor bypassed security perimeters to gain entry to the internal network.
### Lateral Movement
- The unauthorized party moved through "certain portions" of the network between June 11 and June 17 to access stored data.
### Data Exfiltration/Impact
- **Data Accessed:** The actor accessed files containing patient and employee information.
- **Patient Data:** Names, DOB, medical testing info, lab results, health insurance info, and (limited) Social Security numbers.
- **Employee Data:** SSNs, government IDs, and financial account information.
- **Integrity:** Forensic review confirmed no genetic test results were altered or modified.
### Detection & Response
- **Discovery:** June 15, 2026 (Suspicious activity identified).
- **Containment:** Systems were immediately secured upon discovery.
- **Review Completion:** July 30, 2026 (Data mining/individual identification completed).
## Attack Methodology
*Note: Specific technical TTPs were not disclosed in the public notice.*
- **Initial Access:** Unauthorized network access (Method unspecified).
- **Collection:** Gathering sensitive PII/PHI from network storage.
- **Exfiltration:** Accessing and potentially copying data stored on the network.
- **Impact:** Unauthorized access and data exposure (no operational disruption).
## Impact Assessment
- **Financial:** Costs associated with forensic specialists, legal counsel, and notification mailings. Potential for future regulatory fines.
- **Data Breach:** Compromise of PII and PHI for patients and employees (specifically noted 4,532 Rhode Island residents; total count not disclosed).
- **Operational:** Low; laboratory services and testing continued without interruption.
- **Reputational:** Potential loss of trust from third-party medical providers and patients regarding sensitive genetic data.
## Indicators of Compromise
- **Network indicators:** None disclosed in public statement.
- **File indicators:** None disclosed in public statement.
- **Behavioral indicators:** "Suspicious activity" within a limited portion of the IT environment triggered the initial internal alert.
## Response Actions
- **Containment:** Secured affected systems immediately upon discovery.
- **Eradication:** Engaged independent cybersecurity and digital forensic specialists to purge unauthorized access.
- **Recovery:** Conducted a comprehensive forensic investigation and time-intensive data review.
- **Regulatory:** Coordinated with law enforcement and regulatory authorities.
- **Notification:** Provided written notice to affected individuals starting after July 30, 2026.
## Lessons Learned
- **Visibility:** Early detection (within 4 days of initial access) helped limit the scope to a "limited portion" of the environment.
- **Data Segmentation:** The ability to maintain operations suggests that clinical/lab systems were segmented or otherwise isolated from the compromised environment.
- **Notification Lag:** The review process to identify specific impacted individuals took approximately six weeks following the incident.
## Recommendations
- **Identity & Access Management (IAM):** Further strengthen MFA and access controls (as Baylor Genetics has already begun doing).
- **Monitoring:** Enhance continuous security monitoring to reduce the 4-day gap between initial access and discovery.
- **Encryption:** Ensure all sensitive PHI/PII stored on the network is encrypted at rest to mitigate impact in the event of unauthorized access.
- **Data Retention:** Implement strict data retention policies to ensure only necessary sensitive information is stored on the network, reducing the "blast radius" of a breach.