HomeIntelligenceBrief
BREACH BRIEF 🟠 High Breach

Phishing Attack Exposes 225K Patient Records at Ambry Genetics, Triggers $700K HIPAA Fine

Settlement Comes After Firm Paid Nearly $12.3M to Settle Civil Claim for Same Hack A genetics testing lab has agreed to pay a $700,000 HIPAA settlement and improve its security practices in the wake of a 2020 phishing hack that affected 225,370 patients. The firm paid a $12.25 million civil class action settlement in 2023 for the same breach. But the firm faces other legal woes.

Verisq™ Intelligence · 📅 September 22, 2026 · 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
5 recommended
📰
Source
databreachtoday.com

Phishing Attack Exposes 225K Patient Records at Ambry Genetics, Triggers $700K HIPAA Fine

What Happened

In January 2020 a spear‑phishing email compromised employee credentials at Ambry Genetics, allowing attackers to access ePHI for 225,370 patients. The breach was reported to the HHS Office for Civil Rights (OCR) in March 2020. In September 2026 OCR announced a $700,000 civil monetary penalty and a two‑year corrective‑action plan.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how gaps in a formal HIPAA security risk analysis can become a regulatory liability.
  • Highlights the need for documented termination procedures that instantly revoke ePHI access when staff leave or change roles.
  • Shows the importance of unique user identifiers to enable traceable, auditable access to protected health information.

Who Is Affected

  • Healthcare providers and laboratories that store or process genetic test results.
  • Any organization that handles electronic protected health information (ePHI) under HIPAA.
  • Third‑party service providers that integrate with genetics data platforms.

Recommended Actions

  • Conduct a fresh, comprehensive HIPAA security risk analysis and document findings.
  • Verify that termination and role‑change workflows automatically disable ePHI access.
  • Implement unique user IDs across all systems that store or transmit ePHI and ensure they are logged.
  • Review phishing awareness training and simulate attacks to test employee resilience.
  • Request a copy of Ambry’s corrective‑action plan to benchmark your own controls.

Technical Notes

  • Attack vector: Spear‑phishing email leading to credential theft.
  • CVEs: None reported; the breach stemmed from social engineering rather than a software flaw.
  • Data types exposed: Patient name, date of birth, health‑insurance information, medical diagnoses, Social Security numbers for a subset of records, and other clinical details.

Source: DataBreachToday – Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach

📰 Original Source
https://www.databreachtoday.com/ambry-genetics-pays-700k-hipaa-fine-in-phishing-breach-a-32883

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →