Baylor Genetics data breach (2026): was your email exposed?

Baylor Genetics, a clinical genomics lab in Houston, says an intruder reached part of its network in June 2026 and took patient and employee data, including dates of birth, medical testing information, laboratory test results, health insurance details and, for some people, Social Security numbers. State filings account for more than 312,000 people so far, and no nationwide total has been published. Check whether your email was caught up in it — and lock down your accounts before the data is misused.

See which breaches hold my email — free →
Breach date
2026
Publicly disclosed
August 2026
People notified so far
312,000+ notified so far
Website
baylorgenetics.com
An email check won’t confirm this one

This incident is known from Baylor Genetics’s own notice and regulatory filings, not from a set of leaked records that anyone can search. The data was taken, but it hasn’t been published — so no breach-checking tool, ours included, can tell you whether you were in it. The letter is the answer: if one arrived, treat yourself as affected. A free check is still worth running for a different reason — it shows which other breaches already hold your email.

That is the sum of the state notification filings reported so far: 248,430 in Texas, 56,636 in Massachusetts, 4,532 in Rhode Island and 2,630 in Vermont, with California's attorney general also notified. Treat it as a floor rather than a total - Baylor Genetics has not published a nationwide figure, and until one is posted to the federal HHS breach portal the full count is not public. Source: Baylor Genetics' own security notice, the state notification filings reported for Texas, Massachusetts, Rhode Island, Vermont and California, and healthcare and security press reporting between August 14 and 19, 2026.

What happened in the Baylor Genetics breach?

Baylor Genetics is a clinical genomics lab in Houston's Texas Medical Center, a joint venture between Baylor College of Medicine and the Japanese lab group H.U. Group Holdings. It runs the sort of testing most people encounter once and never think about again: whole-genome and exome sequencing, newborn and rare-disease panels, reproductive screening, hereditary-cancer and metabolic tests, ordered by doctors across all 50 states. It is not Baylor College of Medicine itself and not Baylor Scott & White Health, which matters if you are staring at a letter from a lab you have never chosen. According to the company's own notice, someone had access to part of its network between June 11 and June 17, 2026. Staff spotted the activity on or around June 15 and shut it down, the review of whose data had been touched finished on or about July 30, and letters began going out after that. The story reached the press in mid-August.

The company splits what was involved into two groups. For patients: names, plus one or more of date of birth, medical testing information, laboratory test results and health insurance information, with Social Security numbers for what it calls a very limited subset. For current and former employees the list is more familiar and more dangerous - Social Security numbers, government-issued identification numbers and financial account information. Baylor Genetics says it is not aware of any confirmed identity theft, fraud or misuse tied to the incident. No group has claimed the attack publicly, nothing from it has surfaced as a published set of records, lab operations ran without interruption, and the company has not suggested that any test result was altered.

What makes this heavier than the average health-sector notice is the category of data. A password can be changed and a card can be reissued. What a genetics lab holds is a result - that a test was ordered, what it was looking for, and what it found - tied to a name and a date of birth, and none of that rotates or expires. Worth being precise about the limit of what is known: the company describes testing information and laboratory results, not raw sequence files, and it has not said which specific results were in the accessed data. Even so, the fact that a particular test was run on a particular person is enough to make a phone call sound legitimate, and unlike a credit file there is no bureau where you can freeze it.

So the useful steps split the same way. If your letter mentions a Social Security number - the case for employees, and for that limited subset of patients - a credit freeze at all three bureaus is the move that blocks new accounts instead of reporting them after the fact. It is free, and it does not depend on anyone's monitoring offer; healthcare press reported that complimentary credit monitoring was offered to at least some patients, though the public notice names no provider or deadline, so the terms are whatever the letter says. For everyone else the exposure lands on the insurance side, where misuse shows up as an explanation of benefits for care you never had, which is a reason to read those statements rather than file them. And expect calls: a notification wave is always followed by people ringing about your test results or offering to verify your record before it is released, opening with the details already printed in the letter. Baylor Genetics is directing questions to 1-866-200-0985, weekdays 9am to 9pm ET, a number published on its own notice. If someone reaches you first, hang up and dial it yourself.

What data was exposed in the Baylor Genetics breach?

The Baylor Genetics breach exposed names, dates of birth, medical testing information, laboratory test results, health insurance information, social security numbers, government-issued ids and financial account numbers. The more of these are tied to you, the more ways an attacker can impersonate you or break into your other accounts.

NamesDates of birthMedical testing informationLaboratory test resultsHealth insurance informationSocial Security numbersGovernment-issued IDsFinancial account numbers

How the leaked Baylor Genetics data can be used against you

Because the Baylor Genetics breach exposed names, dates of birth, medical testing information, laboratory test results, health insurance information and social security numbers and more, an exposed government ID number is the most dangerous of all, enabling full identity theft; exposed payment details raise the risk of fraudulent charges; and exposed medical and insurance details enable medical identity theft — treatment or prescriptions billed in your name — and make health-themed scam calls far more convincing.

How to check if you were affected

For this one, the notification letter is the only confirmation there is — nothing about it is searchable yet. If you got a letter, use only the contact details printed on it, because scam waves follow every notification rollout. What you can check right now is the rest of your exposure: which known breaches already hold your email, and what leaked in them.

Check my email against known breaches — free →

What to do if your Baylor Genetics account was breached

These steps are prioritized for exactly the kind of data the Baylor Genetics breach exposed.

1
Turn on two-factor authentication

Add 2FA — ideally an authenticator app or a passkey rather than SMS — to your email, banking and other important accounts, so a stolen password alone can’t get in.

2
Watch your finances

Check bank and card statements for charges you don’t recognize, set up transaction alerts, and ask your bank to reissue any card that may have been exposed.

3
Guard against identity theft

A government ID number is high-risk. Consider a credit freeze with the major bureaus so no one can open credit in your name, and turn on identity monitoring.

4
Check your medical bills and insurance statements

Health data misuse shows up as care you never received: a bill, an explanation-of-benefits letter, or a claim on your policy for a treatment that isn’t yours. Read those statements instead of filing them, and query anything unfamiliar with the provider and your insurer — medical identity theft is usually caught this way rather than by credit monitoring.

5
Monitor whether your data resurfaces

Leaked data is resold for years, so a one-time clean-up isn’t enough. Ongoing breach and dark-web monitoring tells you the moment your details reappear, so you can act before an account is misused.

Medical records breached? What to do

Health data has no reset button and no bureau to freeze it at, so the steps differ from a normal breach: read the claims your insurer processes, ask each provider for a copy of your record, and query care you never received.

Read the guide →
Common questions

The Baylor Genetics breach, answered

Was I affected by the Baylor Genetics breach?

Most people caught in this one never chose Baylor Genetics - a doctor or hospital sent the sample there. So the question is not whether the name is familiar, it is whether you had genetic or specialist lab testing done in the US and your provider used them. The notification letter is the only confirmation available: nothing from this incident has been published as a searchable set of records, so no breach-checking tool can answer it, ours included. State filings so far cover more than 312,000 people across Texas, Massachusetts, Rhode Island and Vermont, and no nationwide total has been published - so an empty letterbox today does not mean you are out of it.

Is the Baylor Genetics breach letter I received genuine?

Letters from a real notification rollout do arrive by post and can look alarming. Verify it the safe way: use only the phone number or web address printed on the letter itself, typed in by hand — never a link in an email or text about the breach. Notification waves are followed by scams that copy the wording of the real letter.

What data was involved in the Baylor Genetics breach?

Per the disclosure, the data included names, dates of birth, medical testing information, laboratory test results, health insurance information, social security numbers, government-issued ids and financial account numbers. Affected people: 312,000+ notified so far. That is the sum of the state notification filings reported so far: 248,430 in Texas, 56,636 in Massachusetts, 4,532 in Rhode Island and 2,630 in Vermont, with California's attorney general also notified. Treat it as a floor rather than a total - Baylor Genetics has not published a nationwide figure, and until one is posted to the federal HHS breach portal the full count is not public.

What should I do after the Baylor Genetics breach?

Freeze your credit file with all three bureaus — it is free and, unlike monitoring, it blocks new accounts rather than reporting them afterwards. Take the identity-protection offer in the letter as well, watch medical bills and insurance statements for care you did not receive, and expect phishing that references this breach by name.

When did the Baylor Genetics breach happen?

The incident is dated June 2026 and became public in August 2026. Source: Baylor Genetics' own security notice, the state notification filings reported for Texas, Massachusetts, Rhode Island, Vermont and California, and healthcare and security press reporting between August 14 and 19, 2026.

Is there compensation for this breach?

Breaches this size often end in a class action, and a settlement can take a year or more to reach a claim form. If one opens for Baylor Genetics, it will be run by a court-appointed administrator and announced on the company’s own breach page — never through an unsolicited email asking you to confirm bank details. Our guide to breach settlement claims covers who qualifies, what a payout actually covers, and the deadlines that decide it.

Was your email in the Baylor Genetics breach?

Check free in about a minute — then we’ll help you remove your exposed data and keep it monitored.

Run my free breach check →