Dive Brief:
- Baylor Genetics has experienced a cyberattack involving personal information on its patients and employees.
- The genetic testing company, which disclosed the breach on Friday, said information accessed in the incident included test results, Social Security numbers and financial account details.
- Baylor Genetics is the latest in a series of medtech companies to be hit by cyberattacks, with Medtronic, Stryker, Abbott, Intuitive and iRhythm all disclosing incidents in recent months.
Dive Insight:
Baylor Genetics identified the incident on or around June 15 and completed its review of the situation on or about July 30. An unauthorized third party accessed part of the company’s network and certain data stored on the network between June 11 and June 17.
The investigation revealed that the patient information potentially accessed by the third party varied by individual. In addition to the names of patients, the third party may have seen the individuals’ dates of birth, medical testing information, laboratory test results and potentially health insurance information. For “a very limited subset of patients,” the information may have included Social Security numbers.
Personal identifying information was among the data that the third party may have accessed on current or former employees of Baylor Genetics. The employee information included Social Security numbers, government-issued identification numbers and financial account information.
Baylor Genetics is unaware of any confirmed identity theft, fraud or misuse of personal information related to the incident. However, the company is encouraging potentially impacted individuals to remain vigilant against incidents of identity theft and fraud and to report any suspicious activity immediately. Affected individuals can obtain free annual credit reports.
Baylor Genetics said it has enhanced monitoring and security controls, strengthened identity and access management, and implemented additional safeguards to further protect sensitive information.
The company’s statement about the incident lacks details of how the third party accessed the network and data.