Ambry Genetics Corporation settled with federal regulators in September 2026 over HIPAA Security Rule violations tied to a breach exposing patient health and genetic testing information. The number of affected individuals has not been publicly disclosed. Affected patients should monitor credit reports, watch for phishing, and review medical records for signs of misuse.
| Company | Ambry Genetics Corporation |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Patient Names, Genetic Testing Results, Health and Medical Information, Diagnosis-Related Information, Protected Health Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Unspecified/Unauthorized Access |
| Regulators Notified | Not Publicly Disclosed |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the Ambry Genetics Data Breach?
Federal regulators announced a settlement with Ambry Genetics Corporation in September 2026 over violations of the HIPAA Security Rule. The Ambry Genetics data breach centers on how the company handled sensitive patient information. Ambry is a genetic testing laboratory based in Aliso Viejo, California, and it operates as a covered entity under federal health privacy law.
The settlement followed a federal investigation into how Ambry protected electronic patient records. Investigators looked closely at whether the company met its obligations to secure health data under HIPAA. As a result of that review, regulators found evidence of Security Rule violations connected to the exposure of patient information.
The exact date the underlying breach was discovered has not been publicly disclosed. However, the settlement itself became public in September 2026. Because genetic testing companies handle uniquely sensitive data, the investigation focused heavily on whether Ambry had reasonable safeguards in place to prevent unauthorized access.
The federal review process typically includes forensic analysis of a company’s security practices. In this case, that process led regulators to conclude that Ambry’s practices fell short of HIPAA requirements. This finding is what prompted the formal settlement agreement rather than a contested enforcement action.
Who was affected?
The individuals affected by this breach are patients who used Ambry Genetics for genetic testing services. Because Ambry provides hereditary cancer and other genetic screening, many affected people may have submitted highly personal medical and family health information. This raises the stakes for anyone included in the exposure.
The exact number of affected individuals has not been publicly disclosed. Still, given Ambry’s role as a national genetic testing provider, the population involved could include patients across the United States. In addition, physicians and genetic counselors who ordered tests on behalf of patients may also have had associated records involved.
Because genetic testing often involves entire families, the impact of this breach may extend beyond the individual patient. For example, genetic markers can reveal information relevant to biological relatives as well. This means the true scope of personal impact may be wider than the number of primary account holders.
What Information Was Potentially Exposed?
The nature of Ambry’s business means the information it stores is especially sensitive. Genetic testing companies collect not just standard identifiers but also deeply personal health and biological data. This combination makes the potential exposure more concerning than a typical retail or financial breach.
- Patient names
- Genetic testing results
- Health and medical information
- Diagnosis-related information tied to genetic screening
- Protected health information covered under HIPAA
Because genetic data is permanent and cannot be changed like a password, its exposure carries long-term risk. Unlike a credit card number, a person’s genetic profile cannot be reissued. This means any misuse of this data could have consequences that last far longer than a typical financial data breach.
In addition, exposed health and diagnostic details could be misused for medical identity theft. This occurs when someone uses another person’s health information to obtain medical services or prescriptions fraudulently. Furthermore, sensitive genetic or diagnostic details could lead to discrimination concerns or unwanted disclosure of private health conditions.
What is the company doing?
Following the investigation, Ambry Genetics entered into a settlement agreement with federal regulators. As part of this resolution, the company agreed to address the Security Rule violations identified during the review. This typically includes implementing stronger technical safeguards and updated internal policies.
In connection with this matter, Ambry also filed formal notification with the U.S. Department of Health and Human Services Office for Civil Rights. This filing reflects the company’s acknowledgment of the enforcement action and its commitment to corrective measures. Going forward, Ambry is expected to undergo continued compliance monitoring to verify that its security practices meet HIPAA standards.
These corrective steps often include workforce training, updated risk assessments, and stronger encryption practices. As a result, patients may see increased communication from Ambry regarding how their information is protected moving forward. This ongoing oversight is designed to reduce the chance of a similar incident happening again.
What Should Affected Individuals Do?
Monitor Your Credit Reports
Affected individuals should regularly check their credit reports for unfamiliar activity. This is a simple but effective way to catch identity theft early. You can request free reports from the three major credit bureaus and review them for accounts you did not open.
Because genetic and health data can be paired with other stolen information, monitoring becomes even more important. If you notice unfamiliar inquiries or accounts, report them immediately. Consulting a data breach attorney can also help you understand whether you qualify for compensation related to this incident.
Watch for Phishing and Suspicious Contact
Scammers often use breach news to craft convincing phishing emails or phone calls. Be cautious of any message claiming to be from Ambry Genetics or a related healthcare provider. Never click links or share personal details unless you can verify the sender directly.
Instead, contact Ambry through its official website or verified phone number if you have questions. This helps you avoid falling for a fake message designed to steal further information. Because health-related scams can appear especially convincing, extra caution is warranted here.
Consider a Fraud Alert or Credit Freeze
If your Social Security number or other identifying details were part of your patient file, consider placing a fraud alert on your credit file. This makes it harder for someone to open new accounts in your name. A fraud alert is free and typically lasts one year.
For stronger protection, you can also request a credit freeze with each bureau. This restricts access to your credit file entirely until you lift it. While it takes a few extra steps, a freeze offers one of the strongest defenses against identity theft.
Protect Against Medical Identity Theft
Because genetic and health information was involved, patients should also watch for medical identity theft. This happens when someone uses your health details to receive care or medication under your name. Review any insurance statements or medical bills for services you do not recognize.
If you spot anything unusual, contact your insurance provider and healthcare providers right away. In addition, request a copy of your medical records periodically to confirm accuracy. Catching discrepancies early can prevent long-term complications with your health records and insurance coverage.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
