Genomic-diagnostics firm Baylor Genetics is responding to a cyberattack that compromised some patients’ data, the firm said on Friday.
The intrusion, which occurred between June 11 and June 17, “impacted a limited portion of its information technology environment and certain individuals’ personal information,” the company said in a statement.
Baylor provides laboratory testing for healthcare providers, which means it has amassed a large quantity of private medical data, including test results and genomic records.
The company said the hackers could have accessed patients’ birthdates, medical and laboratory test records, health insurance information and, in a “very limited” number of cases, Social Security numbers. Potentially compromised employee data included Social Security numbers and financial account information.
Baylor’s investigation — for which it hired third-party cybersecurity experts and worked with law enforcement — concluded on July 30, according to the statement, which did not explain the two-week delay in announcing the hack. Following the investigation, Baylor said, it began notifying people whose data the intrusion compromised.
“At this time, Baylor Genetics is not aware of any confirmed identity theft, fraud, or misuse of personal information related to this incident,” the company said.
Baylor also said there was no evidence that the hackers had modified patients’ test results.
Following the intrusion, Baylor said, the company’s security team improved its identity and access management processes and added other security measures.
Baylor did not immediately respond to a request for comment about how the intrusion occurred and what specific security improvements the company was making.
Supply-chain risks proliferate
The Baylor Genetics hack is the latest stark reminder of the supply-chain security risks facing healthcare providers and their patients.
Medical-technology vendors are among the weakest links in the healthcare sector, because they receive far less attention from policymakers, regulators and the general public than frontline healthcare providers such as hospitals and clinics. They are also some of the sector’s most valuable targets for hackers, because their relationships with a wide range of medical providers give them access to reams of sensitive data.
In late July, New Jersey-based diagnostic testing vendor Centers Lab announced that hackers had breached its systems and stolen patient data in August 2025. And two weeks ago, medical-device giant Abbott said a recent cyberattack affected patients’ health data.