Baylor Genetics Data Breach Affected 30,263 Veterans
An unauthorized party accessed sensitive health records in June 2026, forcing a review of security protocols.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust companies to disclose data breaches in a complete and timely manner?
Baylor Genetics suffered a data breach on June 15, 2026, which exposed the personal and medical information of 30,263 veterans. The compromised records included names, lab results, and partial Social Security numbers.
Why it matters
The Department of Veterans Affairs intervened following the incident because the company failed to meet notification expectations, leading to a revision of their Interconnection Security Agreement. The event underscores the critical vulnerabilities inherent in third-party data storage and the necessity for rigorous oversight.
The breach impacted 30,263 records, with 29,483 veterans slated to receive direct mailed notifications. Investigators specifically identified the need to update Amazon Web Services S3 storage access keys as a technical remediation step.
The players
Baylor Genetics
A laboratory service provider that maintains health testing data and infrastructure for clinical and government partners.
Department of Veterans Affairs
The federal agency responsible for managing veteran healthcare and overseeing the security of sensitive service-member data.
Charles River Associates
A global consulting firm that specializes in forensic analysis and incident investigation for high-stakes cybersecurity events.
IDX
A provider of identity-protection services tasked with managing credit monitoring for the affected individuals.
The details
An unauthorized third party gained access to Baylor Genetics' data systems, exposing sensitive health information including dates of birth, insurance details, and medical testing results. Following the discovery, the laboratory implemented additional security measures to secure its infrastructure. The Department of Veterans Affairs subsequently reviewed a forensic incident investigation conducted by Charles River Associates to evaluate the failure.
Timeline
June 15, 2026: An unauthorized party accessed veteran health data.
September 21, 2026: Publication of the incident summary.
The Tech Race
This incident follows a pattern where federal agencies are tightening the requirements of their Interconnection Security Agreements to prevent vendor-side leaks. The update to storage access keys reflects a growing standard in securing cloud-hosted laboratory systems against unauthorized access.
Veterans affected by this breach will receive mailed notifications detailing the scope of their exposed information. Baylor Genetics is currently providing free credit-monitoring and identity-protection services through IDX to help mitigate the risk of fraud.
The takeaway
The Department of Veterans Affairs' decision to revise their security agreement highlights the ongoing struggle to maintain oversight over outsourced medical data. Affected veterans should monitor their financial statements and utilize the credit-monitoring services provided by IDX.
Further reading
For broader trends in incident reporting and data protection, explore our Cybersecurity section.
Live Poll
Do you trust companies to disclose data breaches in a complete and timely manner?









