VYPR
breachPublished Sep 21, 2026· 1 source

Ambry Genetics Fined $700K for HIPAA Violations Following 2020 Phishing Breach

Genetics lab Ambry Genetics will pay $700,000 to settle a HIPAA investigation and implement enhanced security measures after a 2020 phishing attack exposed patient data.

Ambry Genetics has agreed to a $700,000 settlement with the U.S. Department of Health and Human Services' Office for Civil Rights (HHS OCR) to resolve an investigation into a phishing breach that occurred in January 2020. The incident, which Ambry reported in March 2020, compromised the sensitive information of 225,370 patients.

The compromised data included patient names, dates of birth, health insurance information, medical details, and in some cases, Social Security numbers and diagnosis information. HHS OCR's investigation found that Ambry violated several provisions of the HIPAA Security Rule. These violations included failing to conduct a thorough security risk analysis, neglecting to implement proper procedures for terminating access to electronic protected health information (ePHI) for departing employees, and not assigning unique identifiers to track user activity within systems containing ePHI.

As part of the resolution agreement, Ambry Genetics must implement a corrective action plan, which HHS OCR will monitor for two years. This plan mandates a comprehensive security risk analysis, the development of a risk management plan to address identified risks, and the revision of policies to ensure HIPAA compliance. Additionally, the company must implement unique user identification across all IT systems containing ePHI and ensure all workforce members receive training on HIPAA security rule policies and procedures.

This HIPAA settlement is not the only legal challenge Ambry Genetics has faced regarding the 2020 breach. In 2023, the company settled a federal class action lawsuit for the same incident, agreeing to pay $12.25 million. Under that settlement, Ambry committed to paying eligible class members up to $10,000 for documented out-of-pocket costs and providing three years of credit and identity monitoring services, alongside implementing remedial security measures.

Adding to its legal entanglements, Ambry's parent company, Tempus AI, is facing separate class action litigation. This lawsuit alleges that Tempus violated state genetic privacy and medical confidentiality laws when it acquired Ambry in 2025 and transferred sensitive patient genetic data to train its AI models without patient consent. This case highlights growing concerns about the use of genetic data for AI development.

The breach at Ambry Genetics is part of a broader trend of increasing cyberattacks targeting the healthcare and genetics testing sectors. Recent incidents include a significant breach at Baylor Genetics affecting 2.8 million individuals and data theft incidents involving Abbott Laboratories and its cancer diagnostics business, Exact Sciences. These attacks underscore the critical need for robust security practices to protect highly sensitive patient information.

Experts emphasize the unique risks associated with the theft of genetic information. "Theft of genetic information supercharges the risks to victims," stated regulatory attorney Paul Hales. "Genetic information, unique to each individual's health and family history, poses risks that go far beyond routine identity theft, especially in this age of unregulated AI." The potential misuse of such data by malicious actors, particularly in conjunction with advancements in AI, presents a significant and evolving threat landscape.

Synthesized by Vypr AI
Ambry Genetics Fined $700K for HIPAA Violations Following 2020 Phishing Breach · VYPR