Baylor Genetics Data Breach Class Action Lawsuit Investigation
Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Baylor Genetics data breach, which reportedly affected thousands of individuals and may have exposed Names, Dates of birth, Medical-testing information, Laboratory test results, Health-insurance information, and Social Security numbers (for current and former employees: Social Security numbers, Government-issued identification numbers, Financial-account information, and Other personal identifying information).
JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Baylor Genetics, please submit your information to be considered:
You may also open the form here: Baylor Genetics Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.
Baylor Genetics Data Breach: Key Facts
| Company: | Baylor Genetics |
|---|---|
| Location: | Houston, Texas |
| Incident Type: | Data Breach |
| Number Affected: | THOUSANDS, BUT TOTAL NOT YET PUBLICLY CONFIRMED |
| Data Involved: | Names, Dates of birth, Medical-testing information, Laboratory test results, Health-insurance information, and Social Security numbers (for current and former employees: Social Security numbers, Government-issued identification numbers, Financial-account information, and Other personal identifying information) |
| Date Began: | June 11, 2026 |
| Date Discovered: | June 15, 2026 |
| Date Ended: | June 17, 2026 |
| Notice Date: | August 14, 2026 |
| Credit Monitoring: | 12/24 Months of IDX |
| Status: | Class Action Lawsuit Investigation |
What happened in the Baylor Genetics data breach?
Baylor Genetics announced a data breach on August 14, 2026, after determining that an unauthorized third party had accessed portions of its computer network and certain information stored within that environment. Baylor Genetics first detected suspicious activity on or around June 15, 2026. Its investigation later found that the unauthorized access occurred between June 11 and June 17, 2026. The incident affected a limited portion of the company’s information technology environment, according to Baylor Genetics. Baylor Genetics Notice Regarding Cybersecurity Incident
After discovering the suspicious activity, Baylor Genetics secured the affected systems and retained independent cybersecurity and digital-forensics specialists to investigate. The company has not publicly identified the initial means of access or stated whether the incident resulted from phishing, compromised credentials, malware, ransomware, or another specific attack method. Baylor Genetics has also not identified the unauthorized party or disclosed whether it received a ransom demand.
Baylor Genetics conducted a review of the affected data to determine what information was involved and identify the individuals to whom it related. That review was completed on or about July 30, 2026. The company then began providing written notices to potentially affected individuals whose address information was available. A sample Baylor Genetics data breach notice was submitted to the California Attorney General and reported on August 14, 2026. California Baylor Genetics Submitted Breach Notification Sample
The information potentially exposed varied by person. For affected patients, the data may have included names, dates of birth, medical-testing information, laboratory test results, health-insurance information, and, for a limited subset of patients, Social Security numbers. Information involving certain current or former employees may have included Social Security numbers, government-issued identification numbers, financial-account information, and other personal identifiers.
Baylor Genetics reported that its laboratory remained operational throughout the investigation and that the incident did not interrupt its genetic-testing services. The company also stated that it found no evidence that medical-testing data or laboratory results were changed, that existing genetic test results remain accurate, and that patients do not need to be retested because of the incident. As of its announcement, Baylor Genetics said it was not aware of any confirmed identity theft, fraud, or misuse of personal information connected to the breach.
In response, Baylor Genetics reported enhancing its monitoring and security controls, strengthening identity and access-management procedures, implementing additional safeguards, and coordinating with law enforcement and regulatory authorities. The notification letter states that eligible recipients were offered complimentary credit-monitoring and identity-protection services through IDX, with the applicable duration specified in each individual notice. The enrollment deadline listed in the sample notice is November 14, 2026.
Baylor Genetics has not publicly disclosed a nationwide total for the number of people affected. Its official notice states, however, that approximately 4,532 Rhode Island residents may have been impacted. Potentially affected individuals include patients whose information Baylor Genetics received from healthcare providers or other laboratories, as well as certain current and former Baylor Genetics employees.
How did the Baylor Genetics breach occur?
Baylor Genetics has not disclosed the specific technical cause of the breach. According to the company, an unauthorized third party gained access to portions of its computer network and certain information stored there between June 11 and June 17, 2026. Baylor Genetics detected suspicious activity on or around June 15 and then secured the affected systems.
The company has not said whether the attacker entered through phishing, stolen credentials, malware, ransomware, a software vulnerability, or a third-party vendor. It also has not publicly stated whether information was copied or exfiltrated, identifying the incident only as unauthorized access to its network and stored data. Baylor Genetics Notice Regarding Cybersecurity Incident
When did the Baylor Genetics breach occur?
The Baylor Genetics data breach occurred between June 11 and June 17, 2026. Baylor Genetics discovered suspicious activity on or around June 15, 2026, while the unauthorized access was apparently still occurring. Its review of the affected information was completed on or about July 30, 2026, and public notification followed on August 14, 2026. Baylor Genetics Notice Regarding Cybersecurity Incident
How many people were affected by the Baylor Genetics breach?
The nationwide total has not yet been publicly disclosed. Baylor Genetics reports that approximately 4,532 Rhode Island residents may have been affected. Its filing with the California Attorney General also establishes that notices were sent to more than 500 California residents, because California requires submission of a sample notice when more than 500 state residents are notified. The actual nationwide total is likely higher, but an exact figure cannot yet be stated reliably.
What information was exposed in the Baylor Genetics breach?
- The information potentially exposed varied by individual and by whether the person was a patient or an employee. For affected patients, the information may have included:
- Names
- Dates of birth
- Medical-testing information
- Laboratory test results
- Health-insurance information
- Social Security numbers for a limited subset of patients
- For certain current and former Baylor Genetics employees, the information may have included:
- Social Security numbers
- Government-issued identification numbers
- Financial-account information
- Other personal identifying information
Has Baylor Genetics offered free credit monitoring and/or identity theft protection services?
Yes. Baylor Genetics’ sample notification letter states that affected individuals are being offered complimentary credit monitoring and identity-protection services through IDX at no cost. The public template lists the service period as “12/24 months,” which indicates that the duration may vary by recipient. The letter provides an enrollment deadline of November 14, 2026. Recipients must use the unique enrollment code included in their notice to activate the services. The dedicated assistance number is 1-866-200-0985. California Baylor Genetics Submitted Breach Notification Sample
Baylor Genetics data breach timeline:
| Date | Event |
|---|---|
| June 11, 2026 | An unauthorized third party began accessing portions of Baylor Genetics’ computer network and certain information stored within that environment. |
| June 15, 2026 | Baylor Genetics detected suspicious activity. The company secured affected systems, retained independent cybersecurity and digital-forensics specialists, and began investigating the incident. |
| June 17, 2026 | The period of unauthorized network access ended. Baylor Genetics identified the complete access window as June 11 through June 17, 2026. |
| July 30, 2026 | Baylor Genetics completed its review of the affected data to determine what information was involved and identify potentially affected individuals. |
| August 14, 2026 | Baylor Genetics dated and began issuing notification letters to affected individuals. The incident was also publicly reported, and a sample notice was submitted to the California Attorney General. |
| November 14, 2026 | Deadline for eligible notification recipients to enroll in the complimentary credit-monitoring and identity-protection services offered through IDX. |
Who is Baylor Genetics?
Baylor Genetics is a clinical diagnostic laboratory based in Houston’s Texas Medical Center. Established in 2015 as a joint venture involving Baylor College of Medicine and H.U. Holdings, the company provides genetic testing and diagnostic services to healthcare providers and patients throughout the United States. Its services include whole-genome sequencing, whole-exome sequencing, targeted gene panels, and specialized laboratory assays addressing rare diseases, pediatric and reproductive health, hereditary cancer, metabolic disorders, and other genetic conditions. Baylor Genetics: About
What should you do if you received a Baylor Genetics data breach letter?
- If you received a Baylor Genetics data breach notification, consider taking the following steps:
- Confirm that the letter is authentic. Compare its contact information with the official Baylor Genetics security notice (California Baylor Genetics Submitted Breach Notification Sample) or call the dedicated assistance line at 1-866-200-0985. Avoid providing personal information in response to unexpected calls, emails, or text messages about the breach.
- Determine what information was affected. Read the letter carefully because the exposed data varied by individual. It may identify whether your Social Security number, medical-testing information, laboratory results, health-insurance information, government identification, or financial-account information was involved.
- Enroll in the free protection services. Baylor Genetics is offering eligible recipients complimentary credit-monitoring and identity-protection services through IDX. The sample notice lists an enrollment deadline of November 14, 2026. Enrollment requires the unique code contained in the recipient’s letter.
- Consider freezing your credit. A credit freeze can help prevent someone from opening new accounts in your name. Freezes are free, do not affect your credit score, and must be placed separately with Equifax, Experian, and TransUnion. If the notice concerns a minor, a parent or guardian can also request a child credit freeze. FTC: Credit Freezes and Fraud Alerts
- Review your credit reports. Obtain reports from all three credit bureaus through AnnualCreditReport.com and look for unfamiliar accounts, inquiries, addresses, or other activity.
- Monitor financial and medical records. Review bank statements, insurance claims, medical bills, and Explanation of Benefits statements for transactions, services, or providers you do not recognize. Contact the relevant bank, insurer, or healthcare provider promptly if something appears incorrect.
- Watch for breach-related phishing. Criminals may impersonate Baylor Genetics, IDX, healthcare providers, or insurers. Do not disclose an enrollment code, Social Security number, password, or banking information unless you have independently verified the recipient.
- Report suspected identity theft. If your information is misused, report it at IdentityTheft.gov to obtain a personalized recovery plan. You should also notify affected financial institutions and consider filing reports with law enforcement and your state attorney general.
- Preserve relevant records. Keep the notification letter, enrollment confirmation, suspicious communications, credit reports, receipts, and documentation of any time or expenses incurred because of the incident.
Baylor Genetics Sample Data Breach Notice
The sample notice describes the Baylor Genetics data breach, including the type of information that may have been involved and the steps offered to affected individuals.
Open the Baylor Genetics Sample Data Breach Notice in a New Tab
Baylor Genetics Security Update
The Security Update describes the Baylor Genetics data breach, including the type of information that may have been involved and the steps offered to affected individuals.
Open the Baylor Genetics Security Update in a New Tab
Sources and additional information about the data breach:
-
- Baylor Genetics Website
- Baylor Genetics Notice Regarding Cybersecurity Incident
- California Baylor Genetics Submitted Breach Notification Sample
- FTC: Credit Freezes and Fraud Alerts
- AnnualCreditReport.com
- FTC Consumer Advice: Identity Theft
- IdentityTheft.gov
- FTC: Checking Your Credit Report
- IRS Identity Theft Guide for Individuals
- U.S. Department of Health and Human Services Office of Inspector General: Medical Identity Theft
- IdentityTheft.gov: What To Do if Your Information Was Lost or Stolen, or Part of a Data Breach
Class Action FAQ
About This Data Breach Resource
This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Baylor Genetics data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.
This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.
This page is especially relevant for readers searching for information about the Baylor Genetics data breach, Baylor Genetics data breach notice, Baylor Genetics class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.
Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.
The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.
For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?
This website is not associated with nor authorized by Baylor Genetics or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.