Ambry Genetics HIPAA Settlement (225k Affected)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
HHS OCR announced a $700k settlement with Ambry Genetics over a 2020 phishing incident that potentially exposed PHI of 225,370 individuals. Data included names, addresses, DOB, SSNs/driver licenses, financial info, diagnoses, lab results, and treatment information. The settlement addresses identified HIPAA Security Rule violations.
The January 2020 phishing incident at Ambry Genetics has left 225,370 patients with their most sensitive personal and medical information permanently exposed. Names, dates of birth, Social Security numbers, addresses, financial information, medical diagnoses, and lab results were all included in the records potentially accessed through the attack.
Your Name and Date of Birth Cannot Be Changed
Unlike a credit card or password, your legal name and date of birth are fixed identifiers. Once they are paired with a Social Security number, they become a permanent key that fraudsters can use for years to open accounts, file false tax returns, or impersonate you in medical settings. This combination remains valuable long after the initial breach.
What the Exposed Medical Information Enables
The filing lists medical diagnoses and lab results alongside PHI. This data can be used to commit medical identity theft, file fraudulent insurance claims in your name, or build a detailed profile for more sophisticated scams. Because it ties directly to your healthcare history, it is especially useful to criminals targeting insurance or prescription fraud.
No Passwords or Credentials Were Exposed
This incident did not involve the exposure of Ambry Genetics account passwords. You do not need to change any password for this service as a result of this breach. That is one piece of genuinely good news in an otherwise serious exposure.
How to Determine If You Were Affected
Ambry Genetics is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not included. However, if you have moved since January 2020, contact Ambry Genetics directly to confirm whether you were in the group of 225,370 patients whose information was potentially accessed.
The Scale of This Settlement
The U.S. Department of Health and Human Services Office for Civil Rights reached a $700,000 settlement with Ambry Genetics to resolve potential violations of the HIPAA Security Rule connected to this phishing incident. The settlement covers the exposure of protected health information belonging to more than 225,000 people.
What Remains at Risk Long-Term
Because Social Security numbers and dates of birth cannot be reissued like a compromised card, this breach creates lifelong identity theft risk. The combination of financial information with medical diagnoses further increases the chance that your records could be used for insurance fraud or to impersonate you when seeking care.
Concrete Actions That Address This Exposure
- Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name using the exposed SSN and date of birth.
- Review every Explanation of Benefits statement from your health insurer. Look for claims you did not receive care for, as medical identity theft often appears here first.
- Set up IRS Identity Protection PIN for your tax returns. This blocks anyone from filing fraudulent returns using your SSN.
- Monitor your bank and credit card accounts closely for unusual activity, especially any transactions that could relate to medical billing or insurance.
- Contact Ambry Genetics if you moved after January 2020 and have not received notification. Confirm directly whether your records were part of the 225,370 affected.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Ambry Genetics.
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…
Brightspeed Fiber Broadband Incident — January 2026
Crimson Collective ransomware group allegedly stole personal data of over 1 million Brightspeed cust…
Betterment Robo-Advisor 1.4M Customers — January 2026
Robo-advisor Betterment disclosed a breach affecting ~1.4 million customers in January 2026 via a fa…