HHS’ Office for Civil Rights Settles HIPAA Investigation of Ambry Genetics Phishing Attack Affecting 225,000 Individuals - Takeaways - MDSpire
Coming Soon: Introducing MDSpire News. Learn more
Conexiant’s news site is now MDSpire News. Learn more

HHS Office for Civil Rights Reaches Settlement with Ambry Genetics Over HIPAA Breach Linked to Phishing Incident Impacting 225,000 Patients

  • By

  • Office for Civil Rights (OCR)

  • September 17, 2026

Share

  • 1

    Ambry Genetics settled with HHS OCR over a HIPAA breach affecting 225,370 patients due to a phishing attack in January 2020.

  • 2

    The breach involved compromised protected health information, including names, Social Security numbers, and medical records.

  • 3

    HHS OCR found Ambry violated HIPAA Security Rule provisions, including inadequate risk analysis and user access management.

  • 4

    As part of the settlement, Ambry agreed to a corrective action plan and paid $700,000, with OCR monitoring for two years.

  • 5

    OCR emphasizes the importance of risk management and cybersecurity measures to protect electronic protected health information.

Original Source(s)

Related Content