Baylor Genetics disclosed on August 14 that an unauthorized third party accessed portions of its network between June 11 and June 17, 2026. The Houston genetic testing laboratory says it detected suspicious activity on or around June 15, secured the affected systems, and brought in outside forensic specialists. The investigation wrapped on or about July 30.

For patients, the exposed material includes names, dates of birth, medical testing information, laboratory test results, health insurance information, and Social Security numbers for what the company calls a very limited subset. For employees, it includes Social Security numbers, government-issued identification numbers, and financial account information. Baylor Genetics says it is not aware of any confirmed identity theft or misuse, and it has not said how many people the notice covers.

The disclosure followed a familiar arc. Detection came mid-intrusion, scoping the stolen data took another six weeks, and the public notice went out by newswire on a Friday. Trade coverage landed the following week, with MedTech Dive reporting the breach on August 18. Plaintiffs' firms moved faster: Edelson Lechtzin announced a class action investigation on August 16, two days after the notice.

Lab data ages differently from payment data. A card number dies with a reissue, while test results and dates of birth stay accurate for the life of the patient. Permanence makes diagnostics companies dense targets: a genetic testing operation holds more sensitive detail per record than almost any other node in the sector. Baylor Genetics joins a 2026 disclosure list that already includes Medtronic, Stryker, Abbott, Intuitive Surgical, and iRhythm.

One line in the notice deserves a second read. The company says it detected suspicious activity on or around June 15, and the access window it discloses runs through June 17. Two days of overlap between detection and eviction is normal in real incidents. It is also exactly the window an incident response plan is supposed to shrink.