Baylor Genetics data breach (2026): what was exposed and what to do
We publish these pages from public notices and reporting so you can understand what was exposed. Everything here is already public. Always confirm with the organization named in your notice.
What happened
Baylor Genetics, a Texas-based clinical diagnostic and genetic testing laboratory, identified suspicious activity in part of its IT environment on or around June 15, 2026. Its investigation found that an unauthorized third party accessed parts of its network and stored data between June 11 and June 17, 2026. The company finished reviewing the affected data on or about July 30, 2026, and on August 14 it began mailing notice letters and reported the breach to federal and state regulators.
Baylor Genetics reported the breach to the U.S. Department of Health and Human Services as affecting 2,810,878 people. State filings include 2,630 Vermont residents. According to its security update, lab operations continued without interruption, the company found no evidence that test data or results were altered, and it is not aware of any identity theft, fraud, or misuse. No group has publicly claimed the attack.
Affected patients may have had their name, date of birth, medical testing information, lab results, and possibly health insurance information exposed. Social Security numbers were involved for a very limited number of patients. For some current and former employees, Social Security numbers, government ID numbers, and financial account information may have been involved. Baylor Genetics is offering free IDX identity monitoring.
Sources
- Security Update, Baylor Genetics
- Breach Portal, U.S. Department of Health and Human Services Office for Civil Rights
- Submitted Breach Notification Sample: Baylor Genetics, California Attorney General
- Security Breach Notices, Office of the Vermont Attorney General
- Baylor Genetics: ePHI of 2.8M Patients Exposed in Cybersecurity Incident, HIPAA Journal
- 2.8 million people affected by data breach at Baylor Genetics testing and diagnostic firm, TechRadar
What data was exposed
The following types of personal data were compromised:
- Names
- Dates of birth
- Medical testing information and lab results
- Health insurance information (for some patients)
- Social Security numbers (for a very limited number of patients, and for some employees)
- Government-issued ID numbers (for some employees)
- Financial account information (for some employees)
Breach details
| Detail | Value |
|---|---|
| Breach name | Baylor Genetics |
| Date | June 11 to 17, 2026 |
| Disclosed | August 14, 2026 |
| Accounts affected | 2,810,878 (reported to HHS) |
| Domain | baylorgenetics.com |
This summary is compiled from public notices and reporting available when this page was last updated. Figures reflect what those sources report and may change as investigations continue. If something here looks wrong or you think your personal data is involved, contact our support team.
We report breaches as a factual record to help people check their exposure. Inclusion here is not an allegation of wrongdoing or negligence by Baylor Genetics; it reflects a publicly reported security incident.
For whether your personal data was involved and for official remediation offers, rely on notices from the organization named above (or from anyone they say will contact you), not this page alone.
What to do now
Based on the data exposed in this breach, here are the steps you should take:
- If you received a Baylor Genetics notice, enroll in the free IDX monitoring using the code in your letter before the November 14, 2026 deadline.
- If your notice says your Social Security number was involved, or you are a current or former employee, place a free credit freeze with Equifax, Experian, and TransUnion.
- Review Explanation of Benefits statements and lab bills for genetic or diagnostic tests you did not order.
- Be wary of calls or emails that mention a specific genetic test or lab result and ask you to verify insurance or Social Security details. Use contact details from your doctor's office or the Baylor Genetics security update page.
- Current and former employees should check bank accounts used for direct deposit and report unauthorized transfers right away.
- For questions, call the assistance line listed by Baylor Genetics at 1-866-200-0985 (Monday to Friday, 9am to 9pm ET).
What to do after a breach
- A company emailed me about a breach: what should I do?
- Dark web data versus data brokers
- What to do after a data breach
- Got a breach email?
- First 48 hours after a data breach
- Dark web vs. data brokers
- What to do after a data breach
- Premier Medical Group breach
A free Delist scan checks open-web exposure we support: people-search sites, public records, data brokers, and breach-source signals. Signals are not live listings, and this is not removing you from a dump, a DMV database, or a vendor's private ID store.
More breaches
Free personal data exposure scan
We search the open web for your personal data and show what’s exposed. The scan is free. Removal and monitoring require a paid plan.