Phishing Attack Exposes 225K Patient Records at Ambry Genetics, Triggers $700K HIPAA Fine
What Happened
In January 2020 a spear‑phishing email compromised employee credentials at Ambry Genetics, allowing attackers to access ePHI for 225,370 patients. The breach was reported to the HHS Office for Civil Rights (OCR) in March 2020. In September 2026 OCR announced a $700,000 civil monetary penalty and a two‑year corrective‑action plan.
Why It Matters for Compliance & Audit Readiness
- Demonstrates how gaps in a formal HIPAA security risk analysis can become a regulatory liability.
- Highlights the need for documented termination procedures that instantly revoke ePHI access when staff leave or change roles.
- Shows the importance of unique user identifiers to enable traceable, auditable access to protected health information.
Who Is Affected
- Healthcare providers and laboratories that store or process genetic test results.
- Any organization that handles electronic protected health information (ePHI) under HIPAA.
- Third‑party service providers that integrate with genetics data platforms.
Recommended Actions
- Conduct a fresh, comprehensive HIPAA security risk analysis and document findings.
- Verify that termination and role‑change workflows automatically disable ePHI access.
- Implement unique user IDs across all systems that store or transmit ePHI and ensure they are logged.
- Review phishing awareness training and simulate attacks to test employee resilience.
- Request a copy of Ambry’s corrective‑action plan to benchmark your own controls.
Technical Notes
- Attack vector: Spear‑phishing email leading to credential theft.
- CVEs: None reported; the breach stemmed from social engineering rather than a software flaw.
- Data types exposed: Patient name, date of birth, health‑insurance information, medical diagnoses, Social Security numbers for a subset of records, and other clinical details.
Source: DataBreachToday – Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach