Newsweek is a Trust Project member
See more of our trusted coverage when you search.to see more of our trusted coverage when you search.
Patients who underwent genetic testing through Baylor Genetics are being notified after a cybersecurity incident exposed sensitive personal and medical information. Cybersecurity experts warn it could be particularly problematic because the affected people have undergone or are undergoing in vitro fertilization (IVF).
Baylor Genetics disclosed that it identified suspicious activity within a limited portion of its information technology environment in June and later determined that an unauthorized third party had accessed parts of its network between June 11 and June 17. According to the company’s security notice, a review completed on July 30 found that certain patient and employee information may have been exposed, including laboratory test results, health insurance data, and, for some individuals, Social Security numbers.
“Upon identifying the incident, we immediately secured our systems, engaged leading independent cybersecurity and forensic specialists, notified law enforcement, and implemented additional security measures,” Jason Maloni, a spokesperson for Baylor Genetics, told Newsweek.
Baylor Genetics Data Breach: What To Know
Baylor Genetics said it discovered suspicious activity on or around June 15 and immediately launched an investigation with outside cybersecurity and digital forensic specialists. The investigation concluded that an unauthorized third party accessed portions of the company’s network and certain data stored on it between June 11 and June 17.
The company said laboratory operations continued without interruption throughout the incident and that its ability to provide genetic testing services was not affected.
The company sent letters to people who may have been affected this week, informing them of the breach and steps they should take to protect themselves. People who received the letter were encouraged to place a fraud alert on their Social Security number and use credit freezes to ensure no one could use their Social Security number if it was compromised.
“We are pleased to say that our systems are operational, our environment is secure, and our important work with all stakeholders continues as usual,” Maloni said.
Baylor Genetics said it is not currently aware of any confirmed identity theft, fraud, or misuse of personal information linked to the incident. It’s unclear how many people may have had their information leaked, but Baylor Genetics has performed millions of tests.
Why IVF Patients Face Unique Risks
The breach could pose risks beyond traditional identity theft because fertility and genetic-testing information can give criminals personal context that makes scams more convincing.
David de Paula Santos Silva, founder and CEO of CyberX, said attackers could use information about fertility treatment to craft highly targeted fraud attempts. That includes impersonating fertility clinics, genetic testing providers, insurance companies or embryo storage providers. They could claim that an urgent payment is required to continue treatment, release test results or maintain embryo storage.
“IVF also makes this particularly sensitive because people may already be dealing with significant emotional pressure, costs and strict treatment timelines. A message saying that a payment must be made immediately to avoid disrupting treatment could therefore be much more effective than a generic phishing email,” he told Newsweek.
Lewis Berry, principal security architect at Inforcer, echoed those concerns, noting that Social Security information is “absolutely valuable” to a cybercriminal, but the IVF information gives them dangerous specifics.
“If someone knows that you recently had genetic testing done, then they don’t really need to send you the usual vague phishing email,” Berry told Newsweek. “Tell someone there’s an issue with their embryos, their treatment or a payment that needs sorting today and they are probably going to react very differently than they would to a random payment request.”
Given the heightened emotion and stress that surrounds the IVF process, people who may not fall for a generic phishing scam could be vulnerable to a specific scam about their fertility journey. Carl B. Johnson, founder of Cleared Systems, told Newsweek that the stress and time-sensitive nature of decisions involving IVF mean the message doesn’t have to be perfect; it just has to sound familiar enough that the person doesn’t question it.
What Patients Should Do
Experts say affected individuals should proceed cautiously if they receive phone calls, emails or text messages related to fertility treatment, genetic testing or medical billing.
Danny Jenkins, CEO of cybersecurity company ThreatLocker, told Newsweek that scammers frequently rely on urgency to pressure victims into making quick decisions. He encouraged couples to be skeptical of any legitimate-looking email with a threat or a sense of urgency because that’s a warning sign of a scam.
Jenkins said people should call their provider directly using a number they already have to confirm whether it’s legitimate.
Johnson added that people should slow down if they get an email asking for payment. Don’t pay the bill, update payment information or click a link based only on an email, text or phone call. Patients should also watch for credit issues, insurance fraud and be wary of messages that reference fertility care or genetic testing.
For now, Baylor Genetics says it has strengthened security controls, enhanced monitoring, coordinated with law enforcement and regulators, and notified potentially affected individuals. The company maintains that its systems are operational and that it has not identified any confirmed misuse of the exposed data.
Contact Newsweek editors on this story: Sam Wilson.
Request Reprint & Licensing
View Editorial & AI Guidelines
