Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Phishing Attack Exposes 225K Patient Records at Ambry Genetics, Triggers $700K HIPAA Fine

LiveThreat™ Intelligence · 📅 September 22, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
HIGH
🏢
Affected
3 sector(s)
✅
Actions
5 recommended
📰
Source
databreachtoday.com

Phishing Attack Exposes 225K Patient Records at Ambry Genetics, Triggers $700K HIPAA Fine

What Happened

In January 2020 a spear‑phishing email compromised employee credentials at Ambry Genetics, allowing attackers to access ePHI for 225,370 patients. The breach was reported to the HHS Office for Civil Rights (OCR) in March 2020. In September 2026 OCR announced a $700,000 civil monetary penalty and a two‑year corrective‑action plan.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how gaps in a formal HIPAA security risk analysis can become a regulatory liability.
  • Highlights the need for documented termination procedures that instantly revoke ePHI access when staff leave or change roles.
  • Shows the importance of unique user identifiers to enable traceable, auditable access to protected health information.

Who Is Affected

  • Healthcare providers and laboratories that store or process genetic test results.
  • Any organization that handles electronic protected health information (ePHI) under HIPAA.
  • Third‑party service providers that integrate with genetics data platforms.

Recommended Actions

  • Conduct a fresh, comprehensive HIPAA security risk analysis and document findings.
  • Verify that termination and role‑change workflows automatically disable ePHI access.
  • Implement unique user IDs across all systems that store or transmit ePHI and ensure they are logged.
  • Review phishing awareness training and simulate attacks to test employee resilience.
  • Request a copy of Ambry’s corrective‑action plan to benchmark your own controls.

Technical Notes

  • Attack vector: Spear‑phishing email leading to credential theft.
  • CVEs: None reported; the breach stemmed from social engineering rather than a software flaw.
  • Data types exposed: Patient name, date of birth, health‑insurance information, medical diagnoses, Social Security numbers for a subset of records, and other clinical details.

Source: DataBreachToday – Ambry Genetics Pays $700K HIPAA Fine in Phishing Breach

📰 Original Source
https://www.databreachtoday.com/ambry-genetics-pays-700k-hipaa-fine-in-phishing-breach-a-32883 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →