Encryption & Key Management,
Governance & Risk Management,
Security Operations
Settlement Comes After Firm Paid Nearly $12.3M to Settle Civil Claim for Same Hack

In a notable development within the healthcare sector, a genetics testing laboratory located in California, known as Ambry Genetics, has reached a settlement to pay a $700,000 fine under the Health Insurance Portability and Accountability Act (HIPAA). This settlement follows an investigation prompted by a phishing attack in January 2020, which resulted in the unauthorized access to sensitive information of approximately 225,000 patients. The breach included potentially compromised patient names, birth dates, health insurance details, medical records, and in some cases, Social Security numbers and diagnostic information.
This settlement marks a continuation of Ambry Genetics’ legal entanglements surrounding the same breach, as the firm had previously settled a civil class action claim in 2023 for a staggering $12.25 million. Under this prior settlement, affected individuals could receive up to $10,000 each in claims to cover documented out-of-pocket costs stemming from the breach, alongside three years of credit and identity monitoring services.
Furthermore, the genetics lab’s agreement with the U.S. Department of Health and Human Services (HHS) was solidified on September 21, 2026, encompassing not only the monetary penalty but also a commitment to enhance its data security practices. This resolution comes amidst ongoing scrutiny over the company’s data handling and security protocols, highlighting the inadequacies discovered during the HHS Office for Civil Rights (OCR) investigation.
The OCR’s inquiry revealed several violations of the HIPAA security rule. Ambry Genetics was found to have neglected crucial security measures, including an accurate and thorough risk analysis, sufficient procedures for managing access to electronic protected health information (ePHI), and the assignment of unique identifiers for users accessing systems containing ePHI. These lapses in judgment prompted HHS OCR to impose a corrective action plan that Ambry will need to adhere to for the following two years. The plan mandates improvements encompassing risk management strategies, policy revisions, user identification protocols in IT systems, and training for all employees on HIPAA compliance.
Ambry Genetics, however, is not just contending with the fallout from this phishing incident. The parent company, Tempus AI, is currently embroiled in separate proposed class action litigation. This ongoing case alleges that Tempus breached several state laws related to genetic privacy and medical confidentiality when it acquired Ambry in 2025. The litigation asserts that Tempus transferred sensitive genetic information from “hundreds of thousands, if not millions” of Ambry’s patients to train its artificial intelligence models without obtaining proper consent from those individuals.
As these cases unfold, the hacking of genetics testing and healthcare-related firms appears to be escalating. In June of the same year, Baylor Genetics, a Texas-based genomics testing company, fell victim to a hacking incident affecting 2.8 million individuals, further emphasizing the vulnerabilities present in this sector. This breach included sensitive patient information and has raised alarms regarding the growing frequency of cyberattacks targeting genetic data and confidentiality.
Legal experts, including regulatory attorney Paul Hales, have pointed out the profound implications that genetic information theft can have. Hales, who was not directly involved in Ambry’s litigation, stated, “Theft of genetic information supercharges the risks to victims,” highlighting the unique dangers associated with unauthorized access to an individual’s genetic makeup. Such information can potentially be exploited in ways far beyond traditional identity theft, particularly in an era increasingly characterized by unregulated artificial intelligence.
Given these expansive legal challenges and the implications for patient privacy, experts advocate for robust regulations regarding AI to ensure that individuals’ health information remains secure. The proposed class action lawsuit against Tempus AI seeks damages and injunctions against any further unauthorized use or commercialization of genetic information pertaining to plaintiffs and class members, reinforcing the pressing need for accountability in the handling of sensitive health data.