HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals - Summary - MDSpire
Coming Soon: Introducing MDSpire News. Learn more
Conexiant’s news site is now MDSpire News. Learn more

HHS Office for Civil Rights Reaches Settlement with Ambry Genetics Over HIPAA Breach Linked to Phishing Incident Impacting 225,000 Patients

  • By

  • Office for Civil Rights (OCR)

  • September 17, 2026

Share

Objective:

To address possible noncompliance with the HIPAA Security Rule following a phishing incident at Ambry Genetics that potentially exposed the PHI of 225,370 individuals.

Approach:
  • Incident Identification: Ambry identified a phishing attack in January 2020 that compromised an employee’s email account, potentially exposing PHI of 225,370 individuals.
  • Investigation and Findings: The OCR investigated after Ambry's breach report in March 2020 and found violations of the HIPAA Security Rule.
  • Settlement Agreement: Ambry agreed to a corrective action plan and paid $700,000 to OCR.
Key Findings:
  • Ambry failed to perform an accurate, comprehensive risk analysis.
  • Procedures for terminating access to ePHI were not established.
  • Unique identifiers for user tracking in electronic systems were not assigned.
Interpretation:

OCR emphasizes the importance of risk analysis and management in preventing PHI breaches.

Limitations:
  • The article does not provide details on the specific corrective actions taken by Ambry post-settlement.
  • No information on the long-term effectiveness of the measures implemented.
Conclusion:

OCR continues to enforce HIPAA Rules to protect individuals' health information.

Sources:

Original Source(s)

Related Content