Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-19 · updated: 2026-09-19 · tags: [incident, healthcare, phishing] · confidence: high · severity: high · affected_sectors: [healthcare] · au_impact: true

The HHS Office for Civil Rights and California-based genetic testing company Ambry Genetics agreed a settlement resolving alleged HIPAA violations arising from a breach of the electronic protected health information of 225,370 individuals. Ambry will pay a $700,000 penalty and adopt a corrective action plan addressing the non-compliance OCR identified during its investigation. The company detected suspicious activity in its email environment on 22 January 2020; the forensics found an unauthorised third party had accessed an employee's mailbox after the employee responded to a phishing email, with access from 22 to 24 January 2020. The exposed data included names, addresses, dates of birth, driver's licence numbers, diagnosis and condition information, medications, treatment information and some Social Security numbers. The breach was reported to OCR on 22 March 2020 as affecting 232,772 people, a figure later revised down. The delay between the 2020 breach, the 2020 report and a 2026 financial settlement is itself the enforcement signal.

Attribute Detail
Sector Healthcare
Date 2026-09-19
Source HIPAA Journal
Reliability Tier 2