Scope of the Breach
A major data breach at Baylor Genetics has exposed the personal and medical records of approximately 2,810,878 individuals. The company reported this incident to the U.S. Department of Health and Human Services, categorizing the event as a network server hack. This exposure involves highly sensitive data points, including names, Social Security numbers, addresses, dates of birth, and comprehensive medical histories. Patients who underwent prenatal screening, cancer risk assessments, or rare disease diagnostics face significant risks because of the nature of the data involved.
State-level impact varies significantly across the country. Texas residents suffered the heaviest blow, with 248,430 individuals affected. Massachusetts saw 56,636 people impacted, while Illinois reported 50,495 cases. Smaller states also experienced notable consequences, such as Washington with 27,243 affected records and Rhode Island with 4,532 individuals involved. The unauthorized party maintained access to specific network segments between June 11 and June 17, 2026, during which time they viewed or copied data.
Timeline and Discovery
Baylor Genetics first flagged suspicious activity on June 15. The internal review process lasted several weeks, concluding on July 30. Notification letters arrived in mailboxes starting August 14. Many patients may feel confusion regarding the source of these notices. Baylor Genetics operates as both a direct service provider and a partner for third-party laboratories. This partnership model means that some individuals might have received testing through their own physicians without ever directly interacting with the Baylor brand.
Upon discovery, the company secured its internal systems and hired independent cybersecurity specialists to investigate the extent of the intrusion. They claim to have added security layers to their infrastructure, including tighter identity management and updated access controls. As of mid-August, the company maintains that it has no evidence of identity theft or fraud stemming from this specific event. Still, the sheer volume of Social Security numbers in the hands of unauthorized actors necessitates caution for all victims.
Protections and Industry Context
Impacted individuals should review their medical explanation of benefits and monitor credit reports for unauthorized activity. The firm is offering complimentary identity protection and credit monitoring services via IDX to those affected by the breach. Experts often suggest placing a credit freeze with major bureaus to prevent new accounts from opening in a victim's name. This process is free under federal law and serves as a primary defense against the misuse of leaked Social Security numbers.
Health data breaches have become increasingly frequent. Data from the Office for Civil Rights indicates that reports of unsecured health information breaches have trended upward since 2010. The year 2025 marked a record high for such incidents. The scale of the Baylor Genetics incident is large, yet it remains smaller than the massive Change Healthcare breach of July 2024, which affected over 192 million people. The industry average for breach impact sits at roughly 136,300 people per event, making the Baylor incident significantly above average in scale. Consumers should watch for further alerts regarding their medical records or financial accounts throughout the remainder of the year.

