HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals
WASHINGTON — September 17, 2026 — The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) today announced a settlement with Ambry Genetics Corporation (Ambry) concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Ambry, headquartered in Aliso Viejo, California, is a covered entity that provides genetic testing and clinical genomics services.
In January of 2020, Ambry discovered that an employee’s email account was compromised by a phishing attack. The protected health information (PHI) of 225,370 individuals was potentially exfiltrated by the threat actor. Affected PHI included names, addresses, dates of birth, some Social Security numbers or driver’s license numbers, financial information, diagnoses and conditions, lab results, medications, and treatment information.
“Email phishing is a common cyberattack that can lead to a breach of PHI and reveal HIPAA Security Rule deficiencies,” said OCR Director Paula M. Stannard. “Conducting a compliant risk analysis, engaging in risk management, and full implementation of the Security Rule provisions continue to be the foundation for effective cybersecurity and the best cyberdefense.”
OCR enforces the HIPAA Privacy, Security, and Breach Notification Rules, which set forth the requirements that covered entities (health plans, healthcare clearinghouses, and most healthcare providers), and business associates must follow to protect the privacy and security of PHI.
The settlement resolves an investigation that OCR initiated after Ambry filed a breach report in March 2020 about the phishing incident that occurred in January 2020. OCR found that Ambry had potentially violated provisions of the Security Rule, including:
- Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information (ePHI) held by Ambry;
- Failing to implement procedures for terminating access to ePHI when the employment of or other arrangement with a workforce member ends or access is no longer appropriate; and
- Failing to assign a unique name and/or number for identifying and tracking user identity in electronic systems containing ePHI.
Under the terms of the resolution agreement, Ambry agreed to implement a corrective action plan that OCR will monitor for two years and paid $700,000 to OCR. Under the corrective action plan, Ambry has committed to taking steps to ensure compliance with the HIPAA Rules and protect the security of ePHI, including:
- Conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI;
- Develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis;
- Develop, review and, to the extent necessary, revise its current Security Rule policies and procedures to comply with the HIPAA Rules;
- Implement unique user identification in all its information systems that contain ePHI; and
- Ensure that all workforce members are trained with respect to its Security Rule policies and procedures.
OCR recommends that regulated entities, including healthcare providers, health plans, healthcare clearinghouses, and business associates take the following steps to mitigate or prevent cyber-threats:
- Identify where ePHI is located in the organization, including how ePHI enters, flows through, and leaves the organization’s information systems.
- Periodically conduct, and update as needed, a risk analysis and develop and implement a risk management plan to address identified risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
- Ensure audit controls are in place to record and examine information system activity.
- Implement regular review of information system activity.
- Utilize mechanisms to authenticate information to ensure only authorized users are accessing ePHI.
- Encrypt ePHI in transit and at rest to guard against unauthorized access to ePHI when appropriate.
- Incorporate lessons learned from incidents into the organization’s overall security management process.
- Provide workforce members with regular HIPAA training that is specific to the organization and to the workforce members’ respective job duties.
The resolution agreement and corrective action plan may be found at https://www.hhs.gov/sites/default/files/ocr-ra-cap-ambry-genetics-corporation.pdf.
OCR is committed to enforcing the HIPAA Rules that protect the privacy and security of individuals’ health information. The HIPAA Privacy Rule establishes national standards to protect individuals’ PHI; sets limits and conditions on the uses and disclosures of PHI; and gives individuals certain rights, including the right to timely access their health records. The HIPAA Security Rule establishes national standards to protect and secure our healthcare system by requiring administrative, physical, and technical safeguards to ensure the confidentiality, integrity, security, and availability of ePHI. The Risk Analysis provision requires regulated organizations (covered entities and business associates) to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by that organization. Guidance about the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, and the Security Rule’s Risk Analysis requirement, can also be found on OCR’s website.
If you believe that your or another person’s health information privacy or civil rights have been violated, you can file a complaint with OCR.
Follow HHS OCR on X at @HHSOCR.
Like HHS on Facebook, follow HHS on X @HHSgov, @SecKennedy, and sign up for HHS Email Updates.
Last revised: