Houston/ Crime & Emergencies

Houston Genetics Lab Breach Exposes Data of 248,000 Texans, SSNs Included

AI Assisted Icon
Published on August 21, 2026
Houston Genetics Lab Breach Exposes Data of 248,000 Texans, SSNs IncludedSource: Unsplash/Towfiqu barbhuiya

Baylor Genetics has confirmed that a cybersecurity incident exposed the personal information of more than 200,000 Texans, including medical records, financial account details and, in some cases, Social Security numbers. The Houston-based genetic testing laboratory says the breach was identified in June 2026, though the full scope of who was affected has only recently become clear through regulatory filings.

According to the Houston Chronicle, the breach affected 248,430 people in Texas alone, a figure drawn from a report filed with the Texas Attorney General's Office. Baylor Genetics has said it launched an investigation after discovering suspicious activity within a limited portion of its information technology environment, and that it has since notified law enforcement, regulators, and potentially impacted patients and employees about the event.

An official security notice published by the company states that unauthorized access to its network occurred between June 11 and June 17, 2026, with the suspicious activity first identified on June 15. The internal file review was not completed until July 30, meaning public and regulatory notifications did not go out until mid-August, weeks after the intrusion itself was first detected.

What Was Exposed, and Who

The exposed data reportedly includes testing results, lab results and health insurance details, along with financial information such as credit and debit card numbers. Reporting by CyberScoop, cited in HIPAA Journal's coverage, found that current and former Baylor Genetics staff members were impacted alongside clinical patients, with compromised workforce records including Social Security numbers, government IDs and financial account details exposed during the same window of unauthorized access.

The fallout is not confined to Texas. Regulatory disclosures show Baylor Genetics also submitted formal breach notifications to state authorities in California and Vermont, where the Office of the Vermont Attorney General's filings indicate at least 2,630 residents were affected. That multistate reach reflects the laboratory's nationwide operations and the legal requirement in several states to report incidents touching local residents' private data.

Texas law itself sets a low bar for triggering that kind of disclosure. Under the Texas Identity Theft Enforcement and Protection Act, codified in the state's Business and Commerce Code, any business must report a cybersecurity incident affecting 250 or more Texas residents to the Office of the Texas Attorney General, along with details on the nature of the breach and the remedial steps taken.

Company Says Operations Were Not Disrupted

Baylor Genetics says it secured its systems immediately after identifying the incident and engaged independent cybersecurity and forensic specialists to investigate. The company has stated its laboratory operations continued without interruption and that the breach had no impact on its ability to provide genetic testing services. It has also said it is not aware of the exposed information being used for attempted identity theft, fraud or other malicious activity.

For affected individuals, state notification filings with the Commonwealth of Massachusetts show Baylor Genetics is offering 12 to 24 months of complimentary credit monitoring and identity protection services through IDX. Those who qualify receive unique enrollment codes through mailed notices, and the company has set an enrollment deadline of November 14, 2026.

A Lab at the Center of Rare Disease Research

Baylor Genetics is a diagnostic center affiliated with Baylor College of Medicine, headquartered within the Texas Medical Center in Houston and focused on genomics and rare disease identification, including whole-genome and whole-exome sequencing. Formally established in February 2015, it operates as a commercial joint venture between Baylor College of Medicine and Tokyo-based H.U. Group Holdings Inc., formerly known as Miraca Holdings.

The lab bills itself as the largest clinical diagnostic genetic testing laboratory in the country, and Baylor College of Medicine has said it processed more than two petabytes of genomic sequencing data in 2023 alone. Baylor Genetics has also served since 2014 as the national sequencing core for the National Institutes of Health-funded Undiagnosed Diseases Network, a role that puts some of the country's most sensitive medical data through its systems.

Lawyers Circling, Questions Remaining

The breach has already drawn interest from national class action law firms. PR Newswire reported that firms including Edelson Lechtzin LLP and Markovits, Stock & DeMarco, LLC announced legal investigations in mid-August into potential data privacy and security negligence claims, examining whether Baylor Genetics maintained reasonable administrative and technical safeguards.

Several questions remain unresolved. It is not yet clear how the unauthorized third party first gained entry into Baylor Genetics' network, whether any ransom demand was made, or what the full national count of affected individuals looks like beyond the figures reported in Texas and Vermont.

This is not the only major Texas health data incident this year. Hoodline previously reported on a 19,885-patient breach tied to CommuniCare in San Antonio, as well as a separate multi-million-record incident involving vendor Conduent, both of which involved unauthorized access to sensitive patient and health insurance data. Baylor Genetics maintains that its systems are now operational and secure.