Millions of patients warned after DNA testing data breach
Even DNA may be exposed. Clients are outraged.

Image by Cybernews
- Baylor Genetic hacking incident may have exposed data for 2,810,878 people.
- Potentially exposed records include names, birth dates, addresses, Social Security numbers, diagnoses, and lab results.
- The company says attackers accessed parts of its network from June 11th to June 17th, 2026.
- Baylor Genetics says it has not confirmed identity theft or misuse linked to the breach.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Potentially sensitive medical and genetic testing information is among the data exposed.
Houston-based genetic testing company Baylor Genetics has reported a data breach affecting approximately 2.8 million people.
According to a federal breach filing with the US Department of Health and Human Services, 2,810,878 individuals were affected by the incident, which Baylor Genetics classified as a hacking or IT incident involving a network server.
The compromised information may have included names, dates of birth, addresses, Social Security numbers, diagnoses and medical conditions, laboratory results, and other medical testing information.
The breach is particularly sensitive given the nature of Baylor Genetics' business. The company provides genetic testing used in pregnancy and family planning, hereditary cancer risk assessment, rare disease diagnosis, and other deeply personal medical decisions.
Attackers had access for nearly a week
In a notice on its website, Baylor Genetics said it discovered suspicious activity on or around June 15th, 2026, in a limited portion of its IT environment. An investigation determined that an unauthorized third party had accessed portions of the company's network between June 11th and June 17th, nearly a week.
During that period, some data stored on the network was potentially viewed or copied, according to the company.
“At this time, Baylor Genetics is not aware of any confirmed identity theft, fraud, or misuse of personal information related to this incident,” the company said.
Baylor Genetics secured the affected systems after discovering the activity and brought in independent cybersecurity and digital forensic specialists to investigate.
The company said the investigation was completed around July 30th. Notification letters to potentially affected individuals began going out on August 14th.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
No complementary identity protection: clients are not happy
Some Redditors shared that they have received notice letters, even though they had not used the services of Baylor.
“I had a letter come in saying that my information was accessed in a data breach at Baylor Genetics, but I've never had genetic testing. I don't think it's a scam either, as I see a notice on their website and some news stuff,” one Redditor said.
“I hadn’t had testing with Baylor Genetics, but did through Natera. Sounds like they collaborated on a product called Vistara to screen for single-gene disorders. They must have shared pt info as a part of the partnership,” another responded.
Reportedly, the company works with third-party medical providers and can perform testing directly or on behalf of other laboratories, which would explain the confusion.
The company has not offered data protection services, which was met with disappointment.
“Most companies that have this sort of breach try to somehow make it up to the customer by covering 1-3 years of a fraud/identity theft service. These guys were like “you have the right to talk to the credit bureau and freeze your account and get an annual credit report.” Super lame,” one client wrote on Reddit.
The CEOs of these companies should go to prison for their negligence,said another Redditor.
“I received a "Notice of Security Event" basically stating that cybersecurity threats have leaked my data due to shared information technology, even though I never actually agreed to have my results saved, much less shared across other medical systems...how is this even legal?” another raged.
Individuals across states are affected
State records reviewed by Hearst Television's National Consumer Unit indicate that Texas had 248,430 residents affected, Massachusetts 56,636, and Illinois 50,495. Washington reported 27,243 affected residents, and Vermont reported 2,630.
Baylor Genetics' consumer notice also identifies approximately 4,532 Rhode Island residents as potentially affected.