Skip to content
Back to Blog
critical severity August 14, 2026 · 4 min read

Baylor Genetics Data Breach Notice (Washington Attorney General)

If you were named in this filing, here’s what the filing says was exposed, and what to do about it.

Baylor Genetics notified Washington residents of a data breach in a filing reported to the Washington State Attorney General on August 14, 2026, and the notice lists name, full date of birth, health insurance policy or ID number and medical information among the information exposed. The filing puts the incident itself on June 11, 2026.

Baylor Genetics Data Breach Notice (Washington Attorney General)

The filing from Baylor Genetics shows that on June 11, 2026, the personal information of 27,243 people was exposed. The organization notified Washington authorities on August 14, 2026 — 64 days later. This gap between the incident and the official filing is the single most noticeable fact in the record.

Your name, full date of birth, health insurance ID, and medical details are now outside the organization’s control

If you received a letter from Baylor Genetics, those four categories are the ones the filing says were included in the incident. The record does not state that every person had every category exposed, only that these four types of information were involved. Name and full date of birth together create a permanent anchor that cannot be reissued. A health insurance policy or ID number combined with medical information can be used for insurance fraud or medical identity theft, where someone else’s treatment ends up on your record.

No passwords, no Social Security numbers, and no financial account details appear in the exposed categories. That is genuine good news. The absence of those fields means this incident does not put any login credentials at risk and does not require you to change passwords for Baylor Genetics or any linked account.

What full date of birth and medical information actually enable

A complete date of birth never expires. Once it is paired with your name, it can be used to open accounts, request records, or support synthetic identity applications that may surface years from now. Medical information and health insurance IDs raise a different long-term risk: medical identity theft. Someone could seek care using your insurance, have the claims filed under your name, and leave incorrect diagnoses or treatments in your permanent medical file. Correcting those errors often takes longer than fixing a credit report.

The filing does not disclose whether the data was copied and taken or simply viewed. It also does not describe how the incident occurred. Those details remain unknown. What is known is that 27,243 individuals’ records were affected and the four categories listed above are what the organization reported.

How this exposure differs from a typical financial breach

Most people expect a breach to involve credit cards or bank details that can be canceled. Here the sensitive items cannot be canceled. Your date of birth stays the same for life. Your medical history cannot be rewritten. The health insurance identifier can be updated by the insurer, but the underlying medical information tied to it does not disappear from other systems that already received it.

This is why the 64-day interval between June 11 and August 14 matters. The longer the time between an incident and formal notification, the more opportunity exists for the information to be used before anyone can watch for fraud. The record does not label this delay as unusual or acceptable; it simply states both dates. Readers can draw their own conclusion from the timeline printed beside this article.

Determining whether you were affected

Baylor Genetics is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your records were not part of the 27,243 affected. However, if you have moved since June 11, 2026, or changed addresses after that date, a letter may have gone to an old address. In that case, contact Baylor Genetics directly to confirm whether your information was included.

The permanent nature of these records

Unlike a credit card number that can be replaced in days, the combination of name, full date of birth, and medical details creates lifelong exposure. Credit monitoring catches some financial misuse but does not catch someone using your insurance at a doctor’s office or clinic. That misuse can sit undetected for months or years until you notice an unfamiliar claim on an explanation of benefits statement.

The filing lists only the categories above. It does not mention any government identifiers, financial data, or login credentials. This limits the immediate account takeover risk but does not eliminate the longer-term identity and medical fraud risks that come with health-related personal information.

Practical steps that address this specific exposure

  • Review every Explanation of Benefits statement from your health insurer for the next 24 months. Look for claims you did not file or treatment you did not receive. This is the fastest way to catch medical identity theft.
  • Contact your health insurer and ask them to flag your policy for review. Many insurers can add a note requiring extra verification before claims are paid.
  • Place a fraud alert with the three major credit bureaus. Even though no credit information was exposed, the date of birth and name can still support future credit applications in your name.
  • Request a copy of your medical records from Baylor Genetics and from any provider you have seen in the past two years. Verify that no unfamiliar entries have appeared.
  • Monitor your mail and email for any new insurance cards or policy changes you did not request. Fraudsters sometimes try to switch coverage to a new carrier.

The record is limited to what the Washington Attorney General filing states: 27,243 people, four categories of information, incident date of June 11, 2026, and notification on August 14, 2026. No further forensic details are provided. The letter you may or may not have received remains the most direct evidence of whether your specific records were part of this incident.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on Baylor Genetics.

  1. Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
  2. Expect the phone calls to get better. A date of birth is not secret, but it is what call centres use to confirm you are you. Treat any unexpected call that already knows your details as unverified until you call the company back yourself.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Report details & sourcing

Severity Critical identifiers that cannot be reissued, alongside documents or accounts that can be misused now
Disclosed August 14, 2026
Last reviewed August 14, 2026
Affected 27243
Data exposed NameFull Date of BirthHealth Insurance Policy or ID NumberMedical Information
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email