Nearly 2.8 million people have been affected by a cybersecurity incident at Baylor Genetics, with exposed information potentially including medical records, laboratory results, and Social Security numbers.
The Houston-based genetic testing company reported 2,810,878 affected individuals to the US Department of Health and Human Services. The incident was classified as a hacking or IT event involving a network server.
Baylor Genetics discovered suspicious activity around June 15th, 2026. A subsequent investigation found that an unauthorized party had access to parts of its network between June 11th and June 17th. During that period, information stored within the affected environment may have been viewed or copied.
The potentially compromised data varies between individuals. It may include names, home addresses, dates of birth, Social Security numbers, diagnoses, medical conditions, laboratory results, and other information associated with medical testing.
The nature of Baylor Genetics’ services makes some of the exposed information particularly sensitive. The company conducts genetic testing for areas including hereditary cancer risks, rare diseases, pregnancy, and family planning.
After identifying the intrusion, Baylor Genetics secured the affected systems and hired independent cybersecurity and digital forensic specialists. Its investigation concluded around July 30th, and notification letters began being sent to potentially affected individuals on August 14th.
The company said it has not identified confirmed cases of identity theft, fraud, or misuse of personal information resulting from the breach.
Some recipients of the notifications have questioned why Baylor Genetics possessed their information because they did not remember receiving genetic testing directly from the company. Baylor Genetics can conduct testing in connection with other healthcare providers and laboratories, meaning an individual may have had information processed by the company without dealing with it directly.
The incident has also drawn criticism because Baylor Genetics has not offered complimentary identity protection services to affected individuals. Its guidance instead directs people toward measures such as reviewing credit reports and placing fraud alerts or security freezes on their credit files.
Regulatory disclosures provide additional information about the geographic reach of the breach. State records indicate that 248,430 Texas residents were affected, along with 56,636 people in Massachusetts and 50,495 in Illinois. Washington reported 27,243 affected residents, while Baylor Genetics identified approximately 4,532 people in Rhode Island as potentially affected.